CVE-2024-6886: falha crítica em Gitea Open Source Git Server
Inproper Sanitation of field leading to stored XSS
Publicada em
55Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 10epss 33%
probabilidade de exploração
33%top 2% das CVEs
exploração observada
nãonenhuma fonte reporta
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Produtos afetados
Gitea · Gitea Open Source Git ServerCVEs relacionadas — Gitea Open Source Git Server
No mesmo produto, das mais perigosas para as menos.
CVE-2026-20896CRITICALGitea Docker image trusts spoofable reverse-proxy headers by defaultEPSS 2.8%CVE-2026-27771HIGHGitea Composer package source links use insufficient permission checksEPSS 1.4%CVE-2026-26292CRITICALGitea LFS mirror synchronization bypasses migration HTTP transport restrictionsEPSS 0.7%CVE-2026-27780CRITICALGitea pre-receive hook can miss branch-protection checks after scanner errorsEPSS 0.6%CVE-2026-26307HIGHGitea git grep search lacks a timeoutEPSS 0.6%CVE-2026-58422CRITICALImproper authorization on OAuth sign-in callback silently re-enables administrator-disabled accountsEPSS 0.6%