Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS14cTR2LXZycDktdmNmMs4AArco
Cross-site Scripting vulnerability in repository issue list in Gogs
Impact
DisplayName
allows all the characters from users, which leads to an XSS vulnerability when directly displayed in the issue list.
Patches
DisplayName
is sanitized before being displayed. Users should upgrade to 0.12.9 or the latest 0.13.0+dev.
Workarounds
Check and update the existing users' display names that contain malicious characters.
References
N/A
For more information
If you have any questions or comments about this advisory, please post on https://github.com/gogs/gogs/pull/7009.
Permalink: https://github.com/advisories/GHSA-xq4v-vrp9-vcf2JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14cTR2LXZycDktdmNmMs4AArco
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: about 1 year ago
CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Identifiers: GHSA-xq4v-vrp9-vcf2, CVE-2022-31038
References:
- https://github.com/gogs/gogs/security/advisories/GHSA-xq4v-vrp9-vcf2
- https://github.com/gogs/gogs/pull/7009
- https://github.com/gogs/gogs/releases/tag/v0.12.9
- https://nvd.nist.gov/vuln/detail/CVE-2022-31038
- https://github.com/gogs/gogs/commit/155cae1de8916fc3fde78f350763034b7422caee
- https://github.com/advisories/GHSA-xq4v-vrp9-vcf2
Blast Radius: 0.0
Affected Packages
go:gogs.io/gogs
Dependent packages: 2Dependent repositories: 1
Downloads:
Affected Version Ranges: < 0.12.9
Fixed in: 0.12.9
All affected versions: 0.2.0, 0.3.0, 0.3.1, 0.4.0, 0.4.1, 0.4.2, 0.5.0, 0.5.2, 0.5.5, 0.5.8, 0.5.9, 0.5.11, 0.5.13, 0.6.0, 0.6.1, 0.6.3, 0.6.5, 0.6.9, 0.6.15, 0.7.0, 0.7.6, 0.7.19, 0.7.22, 0.7.33, 0.8.0, 0.8.10, 0.8.25, 0.8.43, 0.9.0, 0.9.13, 0.9.46, 0.9.48, 0.9.60, 0.9.71, 0.9.97, 0.9.113, 0.9.128, 0.9.141, 0.10.1, 0.10.8, 0.10.18, 0.11.4, 0.11.19, 0.11.29, 0.11.33, 0.11.34, 0.11.43, 0.11.53, 0.11.66, 0.11.79, 0.11.86, 0.11.91, 0.12.0, 0.12.1, 0.12.2, 0.12.3, 0.12.4, 0.12.5, 0.12.6, 0.12.7, 0.12.8
All unaffected versions: 0.12.9, 0.12.10, 0.12.11, 0.13.0