Product
forgejo
3 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-49948
CVE-2023-49947
CVE-2023-49946
< 1.20.5-1
Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another e
< 1.20.5-1
Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.
< 1.20.5-1
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are bei