Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.
{ "binaries": [ { "binary_name": "golang-code.gitea-git-dev", "binary_version": "0.0~git20171222.4ec3654-3" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11576.json"
{ "binaries": [ { "binary_name": "golang-code.gitea-git-dev", "binary_version": "0.0~git20190411.63b74d4+ds-1" } ] }