CVE-2019-1010314: XSS
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-1010314.
What is the title of the vulnerability?
The title of the vulnerability is 'Gitea 1.7.2 1.7.3 is affected by: Cross Site Scripting (XSS).'
What is the impact of the vulnerability?
The impact is to execute JavaScript in the victim's browser when the vulnerable repository page is loaded.
What is the affected component?
The affected component is the repository's description.
What is the attack vector for this vulnerability?
The attack vector is that the victim must navigate to a public and affected repository page.
Which versions of Gitea are affected?
Gitea versions 1.7.2 and 1.7.3 are affected.
What is the severity of CVE-2019-1010314?
The severity of CVE-2019-1010314 is medium with a CVSS score of 6.1.
How can I fix the vulnerability?
To fix the vulnerability, you should upgrade Gitea to a version that is not affected, such as a version after 1.7.3.
Where can I find more information about the vulnerability?
You can find more information about the vulnerability on the GitHub page for Gitea releases.
What is the CWE category of the vulnerability?
The CWE category of the vulnerability is CWE-79 (Cross-Site Scripting).