跳转到帖子

FreeBSD: VID-F07C8F87-8E65-11EF-81B8-659BF0027D16: forgejo -- multiple vulnerabilities

recommended_posts

发布于
  • Members

FreeBSD: VID-F07C8F87-8E65-11EF-81B8-659BF0027D16: forgejo -- multiple vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
10/28/2024
Created
11/01/2024
Added
10/31/2024
Modified
10/31/2024

Description

Problem Description:

Forgejo generates a token which is used to authenticate web

endpoints that are only meant to be used internally, for instance

when the SSH daemon is used to push a commit with Git.The

verification of this token was not done in constant time and was

susceptible to timing attacks.A pre-condition for such an attack is

the precise measurements of the time for each operation.Since it

requires observing the timing of network operations, the issue is

mitigated when a Forgejo instance is accessed over the internet

because the ISP introduce unpredictable random delays.

Because of a missing permission check, the branch used to propose

a pull request to a repository can always be deleted by the user

performing the merge.It was fixed so that such a deletion is only

allowed if the user performing the merge has write permission to the

repository from which the pull request was made.

Solution(s)

  • freebsd-upgrade-package-forgejo
  • freebsd-upgrade-package-forgejo7
  • 查看数 700
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…