Cross-site Scripting vulnerability in repository issue list in Gogs
Description
Published to the GitHub Advisory Database
Jun 8, 2022
Reviewed
Jun 8, 2022
Published by the National Vulnerability Database
Jun 9, 2022
Last updated
Jan 27, 2023
Impact
DisplayName
allows all the characters from users, which leads to an XSS vulnerability when directly displayed in the issue list.Patches
DisplayName
is sanitized before being displayed. Users should upgrade to 0.12.9 or the latest 0.13.0+dev.Workarounds
Check and update the existing users' display names that contain malicious characters.
References
N/A
For more information
If you have any questions or comments about this advisory, please post on gogs/gogs#7009.
References