Summary
A restricted account can enumerate Limited-visibility organizations and their name, description and avatar by listing the public organization memberships of a known user through GET /api/v1/users/{username}/orgs.
Details
The helper that decides which organization visibilities to include for the viewer returns "Limited" for any signed-in, non-admin, non-self viewer without excluding restricted accounts, so the response admits both public and limited organizations. The single-organization endpoint GET /api/v1/orgs/{org} correctly returns 404 to a restricted viewer for a limited organization; the list path uses a different, unrestricted helper.
Impact
Authorization boundary / confidentiality. A restricted account, which by policy may reach only public content, can discover Limited-visibility organizations and their metadata by walking the public memberships of known users.
Affected versions
Gitea <= 1.27.2.
Patches
Fixed in Gitea 1.27.3 (#39047, #39058).
Workarounds
None. Upgrade to 1.27.3.
Summary
A restricted account can enumerate Limited-visibility organizations and their name, description and avatar by listing the public organization memberships of a known user through
GET /api/v1/users/{username}/orgs.Details
The helper that decides which organization visibilities to include for the viewer returns "Limited" for any signed-in, non-admin, non-self viewer without excluding restricted accounts, so the response admits both public and limited organizations. The single-organization endpoint
GET /api/v1/orgs/{org}correctly returns404to a restricted viewer for a limited organization; the list path uses a different, unrestricted helper.Impact
Authorization boundary / confidentiality. A restricted account, which by policy may reach only public content, can discover Limited-visibility organizations and their metadata by walking the public memberships of known users.
Affected versions
Gitea
<= 1.27.2.Patches
Fixed in Gitea 1.27.3 (#39047, #39058).
Workarounds
None. Upgrade to 1.27.3.