Stored cross-site scripting in syncthing - CVE-2022-46165
Published: August 21, 2023
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when handling filenames in webUI. A remote attacker can trick the victim to synchronize a malicious folder and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Affected software
Fedora
syncthing
How to mitigate CVE-2022-46165
syncthing - addressed in versions 1.23.5-1.el8, 1.23.5-1.el9, 1.23.5-1.fc37, 1.23.5-1.fc38
External References
- https://github.com/syncthing/syncthing/security/advisories/GHSA-9rp6-23gf-4c3h
- https://github.com/syncthing/syncthing/commit/73c52eafb6566435dffd979c3c49562b6d5a4238
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XEBWSQVGHSTR4ZO7LVVEMPEGMV2DS5XR/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IRYGBFJPVBW6PPTETNIBWQJE4HJSA5PJ/