An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.
| Software | From | Fixed in |
|---|---|---|
| gitea / gitea | - | 1.15.7.x |
code.gitea.io/gitea
|
- | 1.6.0 |