Incorrect access control
Synopsis
A vulnerability has been found in Kallithea.
Description
This vulnerability allows a normal user to access the contents of repositories they do not normally have access to.
This issue was found and reported by:
Kacper Szurek (https://security.szurek.pl/).
Resolution
The issue is fixed by Mads Kiilerich in release 0.3.5. Users are advised to upgrade as soon as possible.
To detect a possible breach, users should verify the presence of unexpected newly created repositories inside Kallithea.
Affected versions
As far as we know, the issue is present in all previously released Kallithea versions.
References
- Mercurial changeset fixing the issue https://kallithea-scm.org/repos/kallithea/changeset/fa3365c940644a52e7fc842c83dcca4295ce586b