Summary
An authenticated account marked restricted can retrieve the SSH public keys and GPG keys of a user whose profile visibility is set to Limited, through GET /api/v1/users/{username}/keys and GET /api/v1/users/{username}/gpg_keys. The SSH response exposes key titles, public key material and fingerprints; the GPG response also exposes embedded email addresses. The equivalent web routes (/{user}.keys, /{user}.gpg) correctly deny the same viewer.
Details
The /users/{username} key route group is mounted without the profile-visibility guard used elsewhere, and the key and GPG-key list handlers resolve the target user and return key data without the visibility check that the web handler applies. Restricted users are meant to be treated like anonymous viewers for limited-visibility content.
Impact
Confidentiality only. A restricted viewer can enumerate and read the SSH and GPG keys, fingerprints and GPG-embedded email addresses of any Limited-visibility user on the instance. No organization membership, collaboration, admin right or special token scope is required.
Affected versions
Gitea <= 1.27.2.
Patches
Fixed in Gitea 1.27.3 (#39004, #39039).
Workarounds
None. Upgrade to 1.27.3.
Summary
An authenticated account marked restricted can retrieve the SSH public keys and GPG keys of a user whose profile visibility is set to Limited, through
GET /api/v1/users/{username}/keysandGET /api/v1/users/{username}/gpg_keys. The SSH response exposes key titles, public key material and fingerprints; the GPG response also exposes embedded email addresses. The equivalent web routes (/{user}.keys,/{user}.gpg) correctly deny the same viewer.Details
The
/users/{username}key route group is mounted without the profile-visibility guard used elsewhere, and the key and GPG-key list handlers resolve the target user and return key data without the visibility check that the web handler applies. Restricted users are meant to be treated like anonymous viewers for limited-visibility content.Impact
Confidentiality only. A restricted viewer can enumerate and read the SSH and GPG keys, fingerprints and GPG-embedded email addresses of any Limited-visibility user on the instance. No organization membership, collaboration, admin right or special token scope is required.
Affected versions
Gitea
<= 1.27.2.Patches
Fixed in Gitea 1.27.3 (#39004, #39039).
Workarounds
None. Upgrade to 1.27.3.