Gitea Open Source Git Server Stored XSS Vulnerability
CVE-2024-6886

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
6 August 2024

What is CVE-2024-6886?

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

Affected Version(s)

Gitea Open Source Git Server 1.22.0

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Catalin Iovita (https://github.com/catalin-iovita)
Alexandru Postolache (https://github.com/alex-postolache)
.
CVE-2024-6886 : Gitea Open Source Git Server Stored XSS Vulnerability