CVE-2019-1010261: XSS
Published Jul 18, 2019
·Updated
Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must open a specifically crafted URL. The fixed version is: 1.7.1 and later.
Affected Software
2 affected componentsFixes available
go/code.gitea.io/gitea<=1.7.0
1.7.1
Gitea Gitea<=1.7.0
Remediation
Patch Available
Event History
Jul 18, 2019
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionWeakness
May 24, 2022
Advisory Published
04:50 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-1010261.
2
What is the severity of CVE-2019-1010261?
The severity of CVE-2019-1010261 is medium.
3
What is the impact of CVE-2019-1010261?
The impact of CVE-2019-1010261 is that an attacker is able to have a victim execute arbitrary JavaScript in the browser.
4
How can I fix CVE-2019-1010261?
To fix CVE-2019-1010261, update Gitea to version 1.7.1 or later.
5
Where can I find more information about CVE-2019-1010261?
You can find more information about CVE-2019-1010261 on the NIST website and the GitHub security advisories.