Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-17031
HistorySep 14, 2018 - 2:29 a.m.

Design/Logic Flaw

2018-09-1402:29:00
PRIOn knowledge base
www.prio-n.com
4

0.001 Low

EPSS

Percentile

29.5%

In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an “X-Content-Type-Options: nosniff” header is not sent.

CPENameOperatorVersion
gogseq0.11.53

0.001 Low

EPSS

Percentile

29.5%

Related for PRION:CVE-2018-17031