CVE-2023-49948: Medium severity forgejo vulnerability
Published Dec 3, 2023
·Updated
Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.
Affected Software
1 affected component
Forgejo Forgejo<1.20.5-1
Remediation
Event History
Dec 3, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-49948.
2
What is the severity of CVE-2023-49948?
The severity of CVE-2023-49948 is medium with a severity value of 5.3.
3
What is the affected software of CVE-2023-49948?
The affected software is Forgejo before version 1.20.5-1.
4
How can remote attackers exploit CVE-2023-49948?
Remote attackers can test for the existence of private user accounts by appending .rss (or another extension) to a URL.
5
Is there a fix available for CVE-2023-49948?
Yes, a fix is available. Please update Forgejo to version 1.20.5-1 or later.