Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Forgejo 安全漏洞
Vulnerability Description
Forgejo是一个轻量化git服务。 Forgejo 1.20.5-1之前版本存在安全漏洞。远程攻击者利用该漏洞可以读取私人问题、读取私人拉取请求、删除问题以及执行其他未经授权的操作。
CVSS Information
N/A
Vulnerability Type
N/A