Forgejo v1.18.3-2 has been released as a security update addressing two Git CVEs (CVE-2023-22490 and CVE-2023-23946). The Forgejo security team determined these CVEs cannot be exploited via Forgejo itself, but upgrading is recommended as a precaution. Container image users should pull the new image which bundles a patched git binary (v2.36.5), while binary users should upgrade their system git package to a patched version. The release also includes bug fixes.
Table of contents
Recommended ActionSecurity issues in GitFixing Git when using a Forgejo binaryFixing Git when using a Forgejo container imageForgejo installation instructionsContribute to Forgejo5 Impressions