GHSA-vmp5-c5hp-6c65, CVE-2022-29947
go/github.com/woodpecker-ci/woodpecker
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.
All versions before 0.15.1
Upgrade to version 0.15.1 or above.
2022-05-04
source |