{"id":"GHSA-g95p-88p4-76cm","summary":"Cross-site Scripting in Gitea","details":"Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.","aliases":["BIT-gitea-2021-28378","CVE-2021-28378","GO-2022-0832"],"modified":"2024-08-21T15:57:44.317604Z","published":"2021-09-27T20:17:39Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-09-27T19:23:33Z","nvd_published_at":"2021-03-15T06:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28378"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/pull/14898"},{"type":"WEB","url":"https://github.com/go-gitea/gitea/pull/14899"},{"type":"WEB","url":"https://blog.gitea.io/2021/03/gitea-1.13.4-is-released"},{"type":"WEB","url":"https://github.com/PandatiX/CVE-2021-28378"},{"type":"PACKAGE","url":"https://github.com/go-gitea/gitea"}],"affected":[{"package":{"name":"code.gitea.io/gitea","ecosystem":"Go","purl":"pkg:golang/code.gitea.io/gitea"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-g95p-88p4-76cm/GHSA-g95p-88p4-76cm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}