Remote Information Disclosure in Forgejo Affects User Account Privacy
CVE-2023-49948

5.3MEDIUM

Key Information:

Vendor

Forgejo

Status
Vendor
CVE Published:
3 December 2023

What is CVE-2023-49948?

A vulnerability in Forgejo prior to version 1.20.5-1 enables remote attackers to probe for the existence of private user accounts. This is achieved by appending specific file extensions, such as .rss, to URLs, potentially leading to the exposure of sensitive account information. Organizations using affected Forgejo versions should consider updating promptly to mitigate the associated risks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-49948 : Remote Information Disclosure in Forgejo Affects User Account Privacy