ZeroHour

CVE-2023-49946

CVSS 3.1
9.1 critical
EPSS
<1%p56
Published
()
Modified
Description

In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.

Vendors
forgejo
Products
forgejo
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.