The primary source currently reports high traffic; the details are known only through accounts on Lobsters and Hacker News.
In Forgejo 16.0.4, a .git directory created during variable expansion in a template is removed before a new repository is initialized.
Because of the flaw, variable expansion in a template repository could create a .git directory that Git used during initialization. A malicious template repository could be used to read arbitrary data from the Forgejo host and run processes on it.
Claim check:
- Forgejo 16.0.4 includes a fix for a critical security bug. (confirmed only by the carrying publication: evidence; «Forgejo 16.0.4 has a critical security bug fix (RCE - Remote Code Execution)»)
- Forgejo 16.0.4 removes a .git directory created during variable expansion before a new repository is initialized. (confirmed only by the carrying publication: evidence; «To address this issue, after variable expansion is completed, any existing .git folder is removed from the directory before the git repository is initialized.»)
- Variable expansion in a template repository could create a .git directory that Git used while initializing a new repository. (confirmed only by the carrying publication: evidence; «During this process, variable template expansion could be misused in order to create a new .git folder, which git would adopt and incorporate during its initialization of a new git repository.»)
- A malicious template repository could be used to read arbitrary data from the Forgejo host and run processes on it. (confirmed only by the carrying publication: evidence; «A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack.»)
- The primary source currently reports high traffic. (confirmed by the publication itself: evidence; «This git endpoint is seeing a high influx of requests for this repository, to preserve the availability of Codeberg your search request will not be processed.»)
Publications:
- https://lobste.rs/s/b3cqyr/forgejo_16_0_4_has_critical_security_bug
- https://news.ycombinator.com/item?id=49645907
Primary sources:
score 82.3 out of 100 · kind: incident