Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Our forgejo instance got affected by this. I saw the news and thought we don't need to upgrade (yet), as registration is closed for new users, and users having access is only those we control. As it turns out, when in app.ini we have DISABLE_REGISTRATION = true, it doesn't actually disable registration... Even though no sign in or sign up form was rendered, the attacker used openid registration
as in our config I had
[openid] ENABLE_OPENID_SIGNIN = true ENABLE_OPENID_SIGNUP = true
attacker created a fake openid server, registered this way, created like 100+ repositories, was able to create a superadmin account on forgejo, mint tokens, execute commands from the runner trying to escalate permissions - either via git hooks, or in runner itself. Luckily our runner was running on a separate isolated server, but potential damage could have been much worse.
So yeah, everyone update ASAP if you don't want to spend half a day fixing the consequences (:
by mrnaif - I'm just reading the code here:
Why the `err` isn't carried by the error message? For security? Then maybe log it internally?// Before template expansion, .git was removed so that a fresh repo can be initialized; remove it again in case // some template variable usage has conflicted with this directory and impacts git operations. if err := root.RemoveAll(".git"); err != nil { return fmt.Errorf("unable to remove .git folder") }User/operator can't really fix the problem if you keep giving them information this vague.
by nirui - ``` This git endpoint is seeing a high influx of requests for this repository, to preserve the availability of Codeberg your search request will not be processed. Sorry for the inconvenience and please try again later. ```
Any mirror?
by rcleveng - Relevant change:
Security bug fixes PR: Critical: fix: prevent template expansion from interfering with git repo initialization. When generating a new repository from a template repository, Forgejo clones the template repository, removes the .git folder, performs variable template expansion on files listed in .forgejo/template, and initializes a new git repository. During this process, variable template expansion could be misused in order to create a new .git folder, which git would adopt and incorporate during its initialization of a new git repository. A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack. To address this issue, after variable expansion is completed, any existing .git folder is removed from the directory before the git repository is initialized.by jzebedee - Since the release notes is currently unreadable due to codeberg rate limits, the two fixes in the release notes are:
https://codeberg.org/forgejo/forgejo/pulls/14301:
*Critical:* fix: prevent template expansion from interfering with git repo initialization. When generating a new repository from a template repository, Forgejo clones the template repository, removes the `.git` folder, performs variable template expansion on files listed in `.forgejo/template`, and initializes a new git repository. During this process, variable template expansion could be misused in order to create a new `.git` folder, which git would adopt and incorporate during its initialization of a new git repository. A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack. To address this issue, after variable expansion is completed, any existing `.git` folder is removed from the directory before the git repository is initialized.
https://codeberg.org/forgejo/forgejo/pulls/14301:
ensure authorization reducer is accessed when checking editable PRs in APIs. When editing a git repo contents through Forgejo's API, a specialized security control is used to permit repository maintainers to edit branches that they do not own when an open pull request with the "allow maintainer edit" option is present. This specialized security control did not take into account API-specific security restrictions, such as repo-specific access tokens. As a result, it was possible for an API access token with restricted permission to make modifications outside of that restricted permission. The specialized security control has been updated to take into account API authentication security restrictions.
---
So if like me you run a private forgejo instance with closed signups and limited repository creation, you can wait for the update. Otherwise maybe take it off the public internet for a bit?
by Macha - This was my first thought after they disallowed LLM contributions.
They may not use AI to check for vulnerabilities but attackers are going to which puts themselves at the disadvantage.
by keel-control - Only posting here because I've been asked about it. Gitea is protected against both of these issues.
(bias note: part of project leadership of Gitea)
Edit: As a note, security incidents happen to everyone and we shouldn't shame anyone for reporting them, especially as that'd otherwise cause less issues to be reported overall.
- You should change the URL to https://codeberg.org/forgejo/forgejo/milestone/139655
> PR: Critical: fix: prevent template expansion from interfering with git repo initialization. When generating a new repository from a template repository, Forgejo clones the template repository, removes the .git folder, performs variable template expansion on files listed in .forgejo/template, and initializes a new git repository. During this process, variable template expansion could be misused in order to create a new .git folder, which git would adopt and incorporate during its initialization of a new git repository. A malicious template repository could be used to read arbitrary data from the Forgejo host, and to execute arbitrary processes on the Forgejo host, as a remote code execution attack. To address this issue, after variable expansion is completed, any existing .git folder is removed from the directory before the git repository is initialized.
by amiga386