Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
{
"cpe": "cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.12.0"
},
{
"last_affected": "1.12.6"
},
{
"introduced": "1.13.0"
},
{
"fixed": "1.13.4"
}
],
"source": "CPE_RANGE"
}