Appears on
Articles2
Follow-up on Forgejo disclosure: moderation issues and platform move
Julien Voisin (jvoisin) provides a follow-up to his earlier disclosure about Forgejo, noting that friends were contacted to pressure him, his post was removed from infosec.exchange by a moderator after multiple reports, and he has since moved to mastodon.social. The article appears to be an ongoing personal account of fallout from a security disclosure.
Opinion
Security audit of Forgejo reveals numerous critical vulnerabilities
Security researcher Julien Voisin (jvoisin) conducted a security audit of Forgejo, the Git hosting platform that Fedora recently migrated to from Pagure. The audit revealed numerous critical security vulnerabilities including Server-Side Request Forgery (SSRF) in many places, lack of Content Security Policy (CSP) and Trusted-Types, insecure JavaScript templa
Insight
