Remote Information Disclosure in Forgejo Affects User Account Privacy
CVE-2023-49948
5.3MEDIUM
What is CVE-2023-49948?
A vulnerability in Forgejo prior to version 1.20.5-1 enables remote attackers to probe for the existence of private user accounts. This is achieved by appending specific file extensions, such as .rss, to URLs, potentially leading to the exposure of sensitive account information. Organizations using affected Forgejo versions should consider updating promptly to mitigate the associated risks.
