CVE-2021-28378: XSS
Published Mar 15, 2021
·Updated
Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
Affected Software
2 affected components
Gitea Gitea>=1.12.0<=1.12.6
Gitea Gitea>=1.13.0<1.13.4
Remediation
Patch Available
Event History
Mar 15, 2021
CVE Published
via MITRE·05:20 AM
Data Sourced
via MITRE·05:20 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this Gitea vulnerability?
The vulnerability ID for this Gitea vulnerability is CVE-2021-28378.
2
What is the severity of CVE-2021-28378?
The severity of CVE-2021-28378 is medium.
3
What software versions are affected by CVE-2021-28378?
Gitea versions 1.12.x and 1.13.x before 1.13.4 are affected by CVE-2021-28378.
4
How can an attacker exploit CVE-2021-28378?
An attacker can exploit CVE-2021-28378 by sending certain issue data that contains XSS payloads.
5
How can I fix CVE-2021-28378?
To fix CVE-2021-28378, you should upgrade your Gitea installation to version 1.13.4 or later.