PT-2022-20478 · Gogs · Gogs

Wuhan005

·

Published

2022-06-08

·

Updated

2024-08-21

·

CVE-2022-31038

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gogs versions prior to 0.12.9
Description The issue is related to an XSS vulnerability in the repository issue list of Gogs, an open source self-hosted Git service. In affected versions, the DisplayName does not filter characters input from users, leading to an XSS vulnerability when directly displayed in the issue list. Users are advised to upgrade to resolve the issue. For users unable to upgrade, it is recommended to check their users' display names for malicious characters.
Recommendations For versions prior to 0.12.9, upgrade to 0.12.9 or the latest 0.13.0+dev to resolve the issue. As a temporary workaround, check and update the existing users' display names that contain malicious characters.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-31038
GHSA-XQ4V-VRP9-VCF2
GO-2022-0483

Affected Products

Gogs