Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-6886

Опубликовано: 09 июл. 2024
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

A flaw was found in Gitea. This issue may allow cross-site scripting (XSS) due to improper input sanitization, which can allow an attacker to inject a malicious script into web pages viewed by other users. To exploit this flaw, an attacker must be able to create a repository with malicious settings or modify the settings of an existing repository.

Отчет

This vulnerability is specific to the Gitea server application, which is not shipped or used by any Red Hat products. While some components may use the Gitea Go SDK, the SDK is a client library and is not impacted by this server-side vulnerability.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-api-server-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-artifact-manager-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-cache-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-persistenceagent-containerNot affected
Red Hat OpenShift AI (RHOAI)odh-ml-pipelines-scheduledworkflow-containerNot affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-ml-pipelines-api-server-rhel8Not affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-ml-pipelines-artifact-manager-rhel8Not affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-ml-pipelines-cache-rhel8Not affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-ml-pipelines-persistenceagent-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2303033Gitea: Stored XSS due to improper sanitization

EPSS

Процентиль: 95%
0.16577
Средний

8.8 High

CVSS3

Связанные уязвимости

ubuntu
больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

nvd
больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

debian
больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'C ...

CVSS3: 9.8
github
больше 1 года назад

Gitea Cross-site Scripting Vulnerability

CVSS3: 10
fstec
больше 1 года назад

Уязвимость системы управления Git-репозиториями Gitea, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга

EPSS

Процентиль: 95%
0.16577
Средний

8.8 High

CVSS3