Vulnerability Description
Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Forgejo | Forgejo | < 1.20.5-1 |
References
- https://codeberg.org/forgejo/forgejo/commit/d7408d8b0b04afd2a3c8e23cc908e7bd3849Patch
- https://codeberg.org/forgejo/forgejo/src/branch/forgejo/RELEASE-NOTES.mdRelease Notes
- https://forgejo.org/2023-11-release-v1-20-5-1/Release NotesVendor Advisory
- https://codeberg.org/forgejo/forgejo/commit/d7408d8b0b04afd2a3c8e23cc908e7bd3849Patch
- https://codeberg.org/forgejo/forgejo/src/branch/forgejo/RELEASE-NOTES.mdRelease Notes
- https://forgejo.org/2023-11-release-v1-20-5-1/Release NotesVendor Advisory
FAQ
What is CVE-2023-49948?
CVE-2023-49948 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.
How severe is CVE-2023-49948?
CVE-2023-49948 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49948?
Check the references section above for vendor advisories and patch information. Affected products include: Forgejo Forgejo.