Vulnerability Report: GO-2023-1471
- GHSA-3244-8mff-w398
- Affects: github.com/gotify/server, github.com/gotify/server/v2
- Published: Aug 20, 2024
- Unreviewed
Reflected XSS in Gotify's /docs via import of outdated Swagger UI in github.com/gotify/server
For detailed information about this vulnerability, visit https://github.com/gotify/server/security/advisories/GHSA-3244-8mff-w398.
Affected Modules
-
PathGo Versions
-
all versions, no known fixed
-
before v2.2.3
Aliases
References
- https://github.com/gotify/server/security/advisories/GHSA-3244-8mff-w398
- https://github.com/gotify/server/pull/541
- https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass
- https://www.vidocsecurity.com/blog/hacking-swagger-ui-from-xss-to-account-takeovers
- https://vuln.go.dev/ID/GO-2023-1471.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.