CVE-2023-49946: Critical severity forgejo vulnerability
Published Dec 3, 2023
·Updated
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.
Affected Software
1 affected component
Forgejo Forgejo<1.20.5-1
Event History
Dec 3, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-49946.
2
What is the severity of CVE-2023-49946?
The severity of CVE-2023-49946 is critical with a severity value of 9.1.
3
How does CVE-2023-49946 affect Forgejo?
CVE-2023-49946 affects Forgejo versions up to exclusive version 1.20.5-1.
4
What unauthorized actions can be performed due to CVE-2023-49946?
Due to CVE-2023-49946, remote attackers can read private issues, read private pull requests, delete issues, and perform other unauthorized actions.
5
Are there any known fixes or updates for CVE-2023-49946?
Yes, there is a fix available for CVE-2023-49946, which is included in Forgejo version 1.20.5-1.