This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Git Forges
✓ No known CVEs patched
This release patches 1 known CVE
Topics
bitbucket
ci-cd
devops
docker-registry-v2
git
git-gui
+11 more
git-lfs
git-server
gitea
github
gitlab
go
maven-server
npm-registry
self-hosted
typescript
vue
Affected surfaces
auth
Summary
AI summaryFix prevents reactivating disabled users during OAuth2 login.
Full changelog
-
SECURITY
- fix(auth): do not auto-reactivate disabled users on OAuth2 callback (#38009) (#38183)
-
BUGFIXES
- fix: walk git log context error handling (#38182) (#38185)
Security Fixes
- Fix(auth): Disabled users are no longer auto-reactivated on OAuth2 callback
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About gitea
Git with a cup of tea! Painless self-hosted all-in-one software development service, including Git hosting, code review, team collaboration, package registry and CI/CD
Related context
Related tools
Beta — feedback welcome: [email protected]