CVE-2018-17031: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an “X-Content-Type-Options: nosniff” header is not sent.
References
Detect and mitigate CVE-2018-17031 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →