PT-2022-13907 · Gogs · Gogs
Published
2022-05-05
·
Updated
2024-08-21
·
CVE-2022-1464
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
gogs/gogs versions prior to 0.12.7
Description
The issue is a stored XSS bug in the gogs/gogs GitHub repository. This bug allows the execution of any JavaScript code in a victim's account. The vulnerability is triggered when a user opens an attachment in a public repository, allowing any user to view the report and execute the XSS. The estimated number of potentially affected devices is not specified.
Recommendations
For versions prior to 0.12.7, upgrade to 0.12.7 or the latest 0.13.0+dev to resolve the issue.
As a temporary workaround, consider disabling the upload of SVG files as issue attachments by correctly setting the Content Security Policy for the serving endpoint.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gogs