Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and content.
{
"cpes": [
"cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*"
],
"severity": "Low"
}