x/vulndb: potential Go vuln in github.com/woodpecker-ci/woodpecker: CVE-2022-29947 #440
Labels
excluded: EFFECTIVELY_PRIVATE
This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
CVE-2022-29947 references github.com/woodpecker-ci/woodpecker, which may be a Go module.
Description:
Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.
Links:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: