id: forgejo-repo-exposure info: name: Forgejo Repositories - Exposure author: DhiyaneshDK severity: medium description: | The Forgejo repo is being exposed publically. metadata: verified: true max-request: 1 shodan-query: html:"Forgejo" tags: misconfig,exposure,forgejo http: - method: GET path: - "{{BaseURL}}/explore/repos" matchers-condition: and matchers: - type: word part: body words: - 'Powered by Forgejo' - 'Explore' - 'Repositories' condition: and - type: status status: - 200 # digest: 4a0a0047304502204f611b23d496d29d165afd0ea65d5773544fa8ff3ae5ffbe6f250cb739ae54ee022100cf5238e980463227b0b6cec712441f4ffd5c31a01e63890f8183fdc45deb555a:922c64590222798bb761d5b6d8e72950