CVE-2023-49946
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/12/2023
Last modified:
07/12/2023
Description
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:forgejo:forgejo:*:*:*:*:*:*:*:* | 1.20.5-1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



