The primary source currently reports high traffic; the details are known only through accounts on Lobsters and Hacker News.

In Forgejo 16.0.4, a .git directory created during variable expansion in a template is removed before a new repository is initialized.

Because of the flaw, variable expansion in a template repository could create a .git directory that Git used during initialization. A malicious template repository could be used to read arbitrary data from the Forgejo host and run processes on it.

Claim check:

  • Forgejo 16.0.4 includes a fix for a critical security bug. (confirmed only by the carrying publication: evidence; «Forgejo 16.0.4 has a critical security bug fix (RCE - Remote Code Execution)»)
  • Forgejo 16.0.4 removes a .git directory created during variable expansion before a new repository is initialized. (confirmed only by the carrying publication: evidence; «To address this issue, after variable expansion is completed, any existing .git folder is removed from the directory before the git repository is initialized.»)
  • Variable expansion in a template repository could create a .git directory that Git used while initializing a new repository. (confirmed only by the carrying publication: evidence; «During this process, variable template expansion could be misused in order to create a new .git folder, which git would adopt and incorporate during its initialization of a new git repository.»)
  • A malicious template repository could be used to read arbitrary data from the Forgejo host and run processes on it. (confirmed only by the carrying publication: evidence; «A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack.»)
  • The primary source currently reports high traffic. (confirmed by the publication itself: evidence; «This git endpoint is seeing a high influx of requests for this repository, to preserve the availability of Codeberg your search request will not be processed.»)

Publications:

Primary sources:

score 82.3 out of 100 · kind: incident