Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wpjq-v255-668c

Опубликовано: 01 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.

Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.

EPSS

Процентиль: 48%
0.0025
Низкий

7.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.

EPSS

Процентиль: 48%
0.0025
Низкий

7.8 High

CVSS3

Дефекты

CWE-94