MEDIUM 5.4 Go
Cross-site Scripting vulnerability in repository issue list in Gogs
GHSA-xq4v-vrp9-vcf2 · CVE-2022-31038 · GO-2022-0483
Published · Modified
Description
Impact
DisplayName allows all the characters from users, which leads to an XSS vulnerability when directly displayed in the issue list.
Patches
DisplayName is sanitized before being displayed. Users should upgrade to 0.12.9 or the latest 0.13.0+dev.
Workarounds
Check and update the existing users' display names that contain malicious characters.
References
N/A
For more information
If you have any questions or comments about this advisory, please post on https://github.com/gogs/gogs/pull/7009.
References
- WEB https://github.com/gogs/gogs/security/advisories/GHSA-xq4v-vrp9-vcf2
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-31038
- WEB https://github.com/gogs/gogs/pull/7009
- WEB https://github.com/gogs/gogs/commit/155cae1de8916fc3fde78f350763034b7422caee
- PACKAGE https://github.com/gogs/gogs
- WEB https://github.com/gogs/gogs/releases/tag/v0.12.9
Ready to move
Start Securing
Free, no credit card | First findings in minutes