PT-2020-17182 · Go+1 · Encoding/Xml Package+1

Published

2020-12-14

·

Updated

2024-03-06

·

CVE-2020-29511

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions encoding/xml package in Go (all versions)
Description The issue arises from the encoding/xml package in Go not correctly preserving the semantics of element namespace prefixes during tokenization round-trips. This allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

AZL-6449
AZL-78896
BIT-GOLANG-2020-29511
CVE-2020-29511

Affected Products

Debian
Encoding/Xml Package