VDB
Sign up
CRITICAL9.8

GHSA-4h4p-553m-46qh

Gitea Cross-site Scripting Vulnerability

Quick fix

GHSA-4h4p-553m-46qh — code.gitea.io/gitea: upgrade to the fixed version with the command below.

go get code.gitea.io/gitea@v1.22.1

Details

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/code.gitea.io/gitea
Introduced in: 0Fixed in: 1.22.1
Fixgo get code.gitea.io/gitea@v1.22.1

References