Two-Factor Authentication Bypass in Forgejo by Codethink
CVE-2023-49947
7.5HIGH
What is CVE-2023-49947?
A serious vulnerability in Forgejo prior to version 1.20.5-1 allows attackers to bypass two-factor authentication when using Basic Authentication for Docker login. This flaw creates a significant security risk, as it enables unauthorized access to sensitive data and functionalities, making it imperative for users to update to the latest version to mitigate potential threats.
