Insecure Permissions in Gogs
Moderate severity
GitHub Reviewed
Published
May 18, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
May 18, 2021
Last updated
Jan 9, 2023
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
References