AI analysis
Gitea's web installer can grant an authenticated session for an existing account without verifying that account's password when the installer is reachable against a database that already contains users, such as after INSTALL_LOCK has been reset to false. An attacker submits the install form with an administrator username that matches an existing account and receives a session for that account. If the account is an administrator, the session provides full administrative access, including the ability to change the account's password. Databases with only one user also skipped the reinstall confirmation. No public proof of concept is known and there is no indication of exploitation in the wild.
What to do: Confirm INSTALL_LOCK is true and that the web installer is not reachable on any instance whose database already has users. If the installer was exposed, review administrator sessions and unexpected password changes, then restrict or disable the install endpoint until a vendor fix is applied.
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.