MEDIUM 5.4 Go
Cross-site Scripting in Gitea
GHSA-g95p-88p4-76cm · BIT-gitea-2021-28378 · CVE-2021-28378 · GO-2022-0832
Published · Modified
Description
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-28378
- WEB https://github.com/go-gitea/gitea/pull/14898
- WEB https://github.com/go-gitea/gitea/pull/14899
- WEB https://blog.gitea.io/2021/03/gitea-1.13.4-is-released
- WEB https://github.com/PandatiX/CVE-2021-28378
- PACKAGE https://github.com/go-gitea/gitea
Ready to move
Start Securing
Free, no credit card | First findings in minutes