Critical severity9.1NVD Advisory· Published Dec 3, 2023· Updated Jun 17, 2026
CVE-2023-49946
CVE-2023-49946
Description
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- forgejo.org/2023-11-release-v1-20-5-1/nvdRelease NotesVendor Advisory
- about.gitea.com/securitynvdNot Applicable
- github.com/gogs/gogs/securitynvdNot Applicable
News mentions
0No linked articles in our index yet.