PT-2022-13907 · Gogs · Gogs

Published

2022-05-05

·

Updated

2024-08-21

·

CVE-2022-1464

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions gogs/gogs versions prior to 0.12.7
Description The issue is a stored XSS bug in the gogs/gogs GitHub repository. This bug allows the execution of any JavaScript code in a victim's account. The vulnerability is triggered when a user opens an attachment in a public repository, allowing any user to view the report and execute the XSS. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 0.12.7, upgrade to 0.12.7 or the latest 0.13.0+dev to resolve the issue. As a temporary workaround, consider disabling the upload of SVG files as issue attachments by correctly setting the Content Security Policy for the serving endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1464
GHSA-FF28-F46G-R9G8
GO-2022-0597

Affected Products

Gogs