mirror of
https://codeberg.org/forgejo/forgejo.git
synced 2026-03-25 10:23:02 -04:00
It was possible to hijack attachments during update and create functions to another owner as permissions to check they weren't already attached to another resource and wasn't checked if it belonged to the repository that was being operated on. |
||
|---|---|---|
| .. | ||
| attachment.go | ||
| attachment_test.go | ||