Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-49946

Опубликовано: 03 дек. 2023
Источник: debian
EPSS Низкий

Описание

In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
forgejoitppackage

EPSS

Процентиль: 29%
0.00103
Низкий

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 лет назад

In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.

CVSS3: 9.1
github
около 2 лет назад

In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.

EPSS

Процентиль: 29%
0.00103
Низкий