PT-2020-17181 · Go+2 · Go+2

Published

2020-09-11

·

Updated

2024-03-06

·

CVE-2020-29510

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Go versions 1.15 and earlier
Description The issue arises from the encoding/xml package in Go not correctly preserving the semantics of directives during tokenization round-trips. This allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
Recommendations For Go versions 1.15 and earlier, consider updating to a version that includes the fix for this issue, as the current version does not correctly preserve the semantics of directives during tokenization round-trips. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2766
ALT-PU-2021-1456
ALT-PU-2021-1941
BIT-GOLANG-2020-29510
CVE-2020-29510

Affected Products

Alt Linux
Debian
Go