Note:
This project will be discontinued after December 13, 2021. [more]
2020-06-21
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
Products | Gogs |
Type | Improper Preservation of Permissions (CWE-281) |
First patch | - None (likely due to unavailable code) |
Links |
• https://github.com/gogs/gogs/commit/82ff0c5852f29daa5f95d965fd50665581e7ea3c
• https://github.com/gogs/gogs/pull/5988 |