TGViewer
Linux Linux @sysadminoff · 2.13K subscribers
Post #20032 64
Уязвимость в платформе совместной разработки Forgejo, допускающая удалённое выполнение кода

Опубликованы корректирующие выпуски платформы совместной разработки Forgejo 16.0.4 и 15.0.8, в которых устранена критическая уязвимость (CVE не назначен), позволяющая удалённому атакующему добиться выполнения своего кода на сервере. Администраторам серверов Forgejo рекомендовано срочно обновить свои системы и убедится в отсутствии следов компрометации. Уязвимость вызвана отсутствием должной чистки при создании нового репозитория из шаблона.

👉@sysadminoff

https://www.opennet.ru/opennews/art.shtml?num=66253
More from @sysadminoff
  1. Sep 30, 2026BTR - атака на CPU Intel, AMD и ARM, эксплуатируемая через JIT-компиляторы Группа исследов…
  2. Sep 30, 2026New open-source browser Blanc offers a different UI Blanc is a new open-source browser tha…
  3. Sep 30, 2026📰 Linux 7.3-rc5 Released: "Another Week, Another Large RC" In working toward the stable L…
  4. Sep 30, 2026📰 Steam Beta fixes non-Steam games to failing to launch Now and then a fresh Steam Beta c…
  5. Sep 30, 2026📰 GNOME 49.10 Released as the Final Update in the GNOME 49 Series The final GNOME 49 upda…
  6. Sep 30, 2026📰 FEX code cache enabled for Proton Experimental (ARM) to improve frame timings Valve hav…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →