在 Forgejo 15.0.4 及以下版本中发现了一个漏洞。该问题影响了组件“仓库迁移处理器”(Repository Migration Handler)中 文件里的 函数。通过对该函数进行操作,会导致服务端请求伪造(Server-Side Request Forgery, SSRF)。该攻击可远程发起。利用方法已经公开,且可能被利用。修复补丁的标识为 。建议应用该补丁以修复此问题。项目维护者说明:“由于这是一个破坏性变更(breaking change),我不打算将其回退(backport)到 v15 或 v1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Forgejo | 15.0.0 |
cpe:2.3:a:forgejo:forgejo:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet