Stored cross-site scripting in syncthing - CVE-2022-46165
Published: August 21, 2023
syncthing
syncthing.net
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when handling filenames in webUI. A remote attacker can trick the victim to synchronize a malicious folder and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Remediation
External links
- https://github.com/syncthing/syncthing/security/advisories/GHSA-9rp6-23gf-4c3h
- https://github.com/syncthing/syncthing/commit/73c52eafb6566435dffd979c3c49562b6d5a4238
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XEBWSQVGHSTR4ZO7LVVEMPEGMV2DS5XR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IRYGBFJPVBW6PPTETNIBWQJE4HJSA5PJ/