Description
Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43572 | Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled. |
References
History
Tue, 20 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-05-20T18:33:59.609Z
Reserved: 2022-09-08T00:00:00.000Z
Link: CVE-2022-40274
Updated: 2024-08-03T12:14:40.076Z
Status : Modified
Published: 2022-09-30T17:15:13.217
Modified: 2025-05-20T19:15:47.497
Link: CVE-2022-40274
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD