PT-2023-3322 · Go+10 · Go+10
Juho Nurminen
·
Publicado
2023-04-20
·
Atualizado
2024-12-13
·
CVE-2023-29400
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Go versions (affected versions not specified)
Description
The issue arises from templates containing actions in unquoted HTML attributes, such as "attr={{.}}", which can be executed with empty input, resulting in output with unexpected results when parsed due to HTML normalization rules. This may allow the injection of arbitrary attributes into tags. The vulnerability can be exploited by a remote attacker.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Go
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu