MEDIUM
Cross-site Scripting (XSS) - Stored in go-gitea/gitea
Published May 29, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.79%
Description
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.16.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| GO-Gitea | GO-Gitea/gitea | n/a |
|
No data.
No Red Hat product state for this CVE.
code.gitea.io/gitea
Go
Introduced 0 Fixed 1.16.9
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | code.gitea.io/gitea | 0 | 1.16.9 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4768 Advisory
- https://github.com/advisories/GHSA-ph3w-2843-72mx Advisory
- https://github.com/go-gitea/gitea/commit/65e0688a5c9dacad50e71024b7529fdf0e3c2e9c PatchThird Party Advisory
- https://github.com/go-gitea/gitea/pull/19825
- https://huntr.dev/bounties/6336ec42-5c4d-4f61-ae38-2bb539f433d2 ExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1928
- https://security.gentoo.org/glsa/202210-14 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4768 | Advisory | |
| https://github.com/advisories/GHSA-ph3w-2843-72mx | Advisory | |
| https://github.com/go-gitea/gitea/commit/65e0688a5c9dacad50e71024b7529fdf0e3c2e9c | PatchThird Party Advisory | |
| https://github.com/go-gitea/gitea/pull/19825 | ||
| https://huntr.dev/bounties/6336ec42-5c4d-4f61-ae38-2bb539f433d2 | ExploitPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1928 | ||
| https://security.gentoo.org/glsa/202210-14 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published May 29, 2022
Updated Aug 3, 2024
Reserved May 28, 2022
Link CVE-2022-1928
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-4768 GHSA-PH3W-2843-72MX Assigner @huntrdev
Published May 29, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-4768