In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/gogs/gogs/issues/5397 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-09-14T02:00:00
Updated: 2024-08-05T10:39:59.632Z
Reserved: 2018-09-13T00:00:00
Link: CVE-2018-17031
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-09-14T02:29:00.390
Modified: 2024-11-21T03:53:44.420
Link: CVE-2018-17031
Redhat
No data.