Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/syncthing/syncthing
  4. ›
  5. CVE-2022-46165

CVE-2022-46165: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

June 6, 2023 (updated June 16, 2023)

Syncthing is an open source, continuous file synchronization program. In versions prior to 1.23.5 a compromised instance with shared folders could sync malicious files which contain arbitrary HTML and JavaScript in the name. If the owner of another device looks over the shared folder settings and moves the mouse over the latest sync, a script could be executed to change settings for shared folders or add devices automatically. Additionally adding a new device with a malicious name could embed HTML or JavaScript inside parts of the page. As a result the webUI may be subject to a stored cross site scripting attack. This issue has been addressed in version 1.23.5. Users are advised to upgrade. Users unable to upgrade should avoid sharing folders with untrusted users.

References

  • github.com/advisories/GHSA-9rp6-23gf-4c3h
  • github.com/syncthing/syncthing/commit/73c52eafb6566435dffd979c3c49562b6d5a4238
  • github.com/syncthing/syncthing/commit/f5e5af391a6583047c64ef8c51642003a79b75cf
  • github.com/syncthing/syncthing/releases/tag/v1.23.5
  • github.com/syncthing/syncthing/security/advisories/GHSA-9rp6-23gf-4c3h
  • lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IRYGBFJPVBW6PPTETNIBWQJE4HJSA5PJ/
  • lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XEBWSQVGHSTR4ZO7LVVEMPEGMV2DS5XR/
  • nvd.nist.gov/vuln/detail/CVE-2022-46165

Code Behaviors & Features

Detect and mitigate CVE-2022-46165 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.23.5

Fixed versions

  • v1.23.5

Solution

Upgrade to version 1.23.5 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

go/github.com/syncthing/syncthing/CVE-2022-46165.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:25 +0000.