MEDIUM 6.1 Go
Gitea XSS Vulnerability in Repository Description
GHSA-hqx2-j33x-9fc4 · CVE-2019-1010314
Published · Modified
Description
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2019-1010314
- WEB https://github.com/go-gitea/gitea/issues/8717
- WEB https://github.com/go-gitea/gitea/pull/6306
- WEB https://github.com/go-gitea/gitea/pull/6308
- WEB https://github.com/go-gitea/gitea/commit/c7bbfd8f5eb097c6910e142415fcdf48fc3c9814
- PACKAGE https://github.com/go-gitea/gitea
- WEB https://github.com/go-gitea/gitea/releases/tag/v1.7.4
Ready to move
Start Securing
Free, no credit card | First findings in minutes