Количество 2
Количество 2
CVE-2022-31038
Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved in commit 155cae1d which sanitizes `DisplayName` prior to display to the user. All users of gogs are advised to upgrade. Users unable to upgrade should check their users' display names for malicious characters.
GHSA-xq4v-vrp9-vcf2
Cross-site Scripting vulnerability in repository issue list in Gogs
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-31038 Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved in commit 155cae1d which sanitizes `DisplayName` prior to display to the user. All users of gogs are advised to upgrade. Users unable to upgrade should check their users' display names for malicious characters. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-xq4v-vrp9-vcf2 Cross-site Scripting vulnerability in repository issue list in Gogs | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу