CVE-2023-49947: High severity forgejo vulnerability
Published Dec 3, 2023
·Updated
Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.
Affected Software
1 affected component
Forgejo Forgejo<1.20.5-1
Remediation
Event History
Dec 3, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-49947?
CVE-2023-49947 is a vulnerability in Forgejo before version 1.20.5-1 that allows bypassing 2FA when docker login uses Basic Authentication.
2
How severe is CVE-2023-49947?
CVE-2023-49947 has a severity rating of 7.5, which is considered high.
3
How can the 2FA bypass issue be fixed in Forgejo?
To fix the 2FA bypass issue in Forgejo, users should update to version 1.20.5-1 or a newer version.
4
Where can I find more information about CVE-2023-49947?
You can find more information about CVE-2023-49947 in the following references: [link1](https://forgejo.org/2023-11-release-v1-20-5-1/) and [link2](https://codeberg.org/forgejo/forgejo/commit/44df78edd40076b349d50dc5fb02af417a44cfab).
5
What is the CWE for CVE-2023-49947?
The CWE (Common Weakness Enumeration) for CVE-2023-49947 is CWE-863.