User Login Time Disclosure in Gitea
CVE-2025-68943
5.3MEDIUM
What is CVE-2025-68943?
In Gitea versions prior to 1.21.8, a vulnerability exists that can lead to the unintended disclosure of users' login times. This occurs through the exploitation of the sort order on the last login time within the explore/users feature. As a result, unauthorized users may gain insights into user activity, posing a potential privacy risk. It is crucial for users to upgrade to the latest version to mitigate this security concern.
Affected Version(s)
Gitea 0 < 1.21.8
