9.1

CVE-2023-49946

In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ForgejoForgejo Version < 1.20.5-1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.87% 0.539
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

https://about.gitea.com/security
Not Applicable
https://codeberg.org/forgejo/forgejo/src/branch/forgejo/RELEASE-NOTES.md
Vendor Advisory
Release Notes
https://forgejo.org/2023-11-release-v1-20-5-1/
Vendor Advisory
Release Notes
https://github.com/gogs/gogs/security
Not Applicable