CVE-2014-8683: XSS
Published Nov 21, 2014
·Updated
Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.8 allows remote attackers to inject arbitrary web script or HTML via the text parameter to api/v1/markdown.
Affected Software
6 affected components
Gogits Gogs<=0.5.5
Gogits Gogs=0.3.1-9
Gogits Gogs=0.4.1
Gogits Gogs=0.4.2
Gogits Gogs=0.5.0
Gogits Gogs=0.5.2
Event History
Nov 21, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8683?
CVE-2014-8683 is classified as a medium severity cross-site scripting vulnerability.
2
What versions of Gogs are affected by CVE-2014-8683?
CVE-2014-8683 affects Gogs versions from 0.3.1-9 to 0.5.5, excluding version 0.5.8 and later.
3
How do I fix CVE-2014-8683?
To fix CVE-2014-8683, upgrade Gogs to version 0.5.8 or later.
4
What type of vulnerability is CVE-2014-8683?
CVE-2014-8683 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
5
What is the impact of CVE-2014-8683?
The impact of CVE-2014-8683 includes the potential for attackers to execute malicious scripts in the context of a user's browser.