OSV 1.4.0 · github-reviewed · 修改于 2026-07-21 21:40
发布时间
2026-06-24 01:13
GitHub 审查时间
2026-06-24 01:13
NVD 发布时间
2026-06-25 05:16
源文件
advisories/github-reviewed/2026/06/GHSA-744x-3838-5r56/GHSA-744x-3838-5r56.json
Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v1/org_team.go:8 returns all teams for any organization without requiring authentication. The route group at internal/route/api/v1/api.go:380-385 lacks the reqToken() middleware, and the listTeams() handler performs no authentication check, exposing team IDs, names, descriptions, and permission levels to any unauthenticated caller.
Gogs (all current versions)
internal/route/api/v1/api.go lines 380-385:
// Org teams route group — no reqToken() middleware
m.Group("/:orgname", func() {
m.Get("/teams", org.ListTeams) // No auth required
}, orgAssignment(true))
The orgAssignment(true) middleware only loads the organization object — it performs no authentication. The listTeams() handler at org_team.go:8 returns all teams unconditionally:
func ListTeams(c *context.APIContext) {
org := c.Org.Organization
teams, err := database.GetTeamsByOrgID(org.ID)
// Returns all teams — no c.IsLogged check, no permission check
}
Compare with other org endpoints that correctly require authentication:
m.Group("/orgs/:orgname", func() {
// ... other endpoints ...
}, reqToken(), orgAssignment(true, true)) // reqToken() enforces auth
GET /api/v1/orgs/target-org/teams with no authenticationorgAssignment(true) loads the organization but does not check authListTeams() queries all teams and returns them# List all teams in an organization — no authentication needed
curl -s "http://TARGET:3000/api/v1/orgs/myorg/teams" | python3 -m json.tool
# Expected: 200 OK with full team list
# [
# {
# "id": 1,
# "name": "Owners",
# "description": "Admin team",
# "permission": "owner"
# },
# {
# "id": 2,
# "name": "backend-devs",
# "description": "Backend development team",
# "permission": "write"
# }
# ]
An unauthenticated attacker can:
m.Group("/:orgname", func() {
m.Get("/teams", org.ListTeams)
}, reqToken(), orgAssignment(true))
Add reqToken() middleware to the org teams route group, consistent with other authenticated org endpoints. Additionally, ListTeams() should verify the authenticated user is a member of the organization.