Forgejo closes a patch-apply RCE that the last fix missed
v16.0.5 and v15.0.9, both out 17 September, patch a critical RCE reached by applying a patch, plus a CSRF that could attach an unexpected OpenID identity to a logged-in account.
1 story on this subject, newest first.
v16.0.5 and v15.0.9, both out 17 September, patch a critical RCE reached by applying a patch, plus a CSRF that could attach an unexpected OpenID identity to a logged-in account.