-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| code.gitea.io/gitea | go | < 1.8.0 | 1.8.0 |
The vulnerability stemmed from missing 2FA enforcement in API authentication flows. The GitHub PRs #6674/6676 show critical changes adding OTP checks to API context handlers. Specifically: