The vendor explicitly states that these products are not affected by this CVE.
- openshift-pipelines-client.src as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-cli-tkn-rhel9 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-opc-rhel9 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-pipelines-as-code-cli-rhel9 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9 as a component of OpenShift Pipelines
- Summary
- A flaw was found in Gitea. An attacker can reactivate an administrator-deactivated account by signing in via OAuth2, specifically when using authentication sources that do not utilize refresh tokens. This bypasses intended security controls, allowing unauthorized access to previously deactivated accounts.
- Remediation
- No remediation text is recorded.
