CVE-2023-49946

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/12/2023
Last modified:
07/12/2023

Description

In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:forgejo:forgejo:*:*:*:*:*:*:*:* 1.20.5-1 (excluding)