MEDIUM
Stored xss bug in gogs/gogs
Published May 5, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.72%
Description
Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .
Affected products
-
Affected
- ≥ unspecified, < 0.12.7
No data.
No Red Hat product state for this CVE.
gogs.io/gogs
Go
Introduced 0 Fixed 0.12.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | gogs.io/gogs | 0 | 0.12.7 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3755 Advisory
- https://github.com/advisories/GHSA-ff28-f46g-r9g8 Advisory
- https://github.com/gogs/gogs/commit/bc77440b301ac8780698be91dff1ac33b7cee850 x_refsource_MISCPatchThird Party Advisory
- https://github.com/gogs/gogs/security/advisories/GHSA-ff28-f46g-r9g8
- https://huntr.dev/bounties/34a12146-3a5d-4efc-a0f8-7a3ae04b198d x_refsource_CONFIRMExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1464
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3755 | Advisory | |
| https://github.com/advisories/GHSA-ff28-f46g-r9g8 | Advisory | |
| https://github.com/gogs/gogs/commit/bc77440b301ac8780698be91dff1ac33b7cee850 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/gogs/gogs/security/advisories/GHSA-ff28-f46g-r9g8 | ||
| https://huntr.dev/bounties/34a12146-3a5d-4efc-a0f8-7a3ae04b198d | x_refsource_CONFIRMExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1464 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published May 5, 2022
Updated Aug 3, 2024
Reserved Apr 25, 2022
Link CVE-2022-1464
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-FF28-F46G-R9G8