The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Golang
Subscribe
|
Go
Subscribe
|
|
Redhat
Subscribe
|
Acm
Subscribe
Enterprise Linux
Subscribe
Migration Toolkit Virtualization
Subscribe
Multicluster Engine
Subscribe
Network Observ Optr
Subscribe
Openshift
Subscribe
Openshift Api Data Protection
Subscribe
Openshift Data Foundation
Subscribe
Openshift Distributed Tracing
Subscribe
Openshift Secondary Scheduler
Subscribe
Openstack
Subscribe
Rhmt
Subscribe
Run Once Duration Override Operator
Subscribe
Service Interconnect
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43050 | The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack. |
Ubuntu USN |
USN-6574-1 | Go vulnerabilities |
Ubuntu USN |
USN-7061-1 | Go vulnerabilities |
Ubuntu USN |
USN-7109-1 | Go vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Distributed Tracing
|
|
| CPEs | cpe:/a:redhat:acm:2.6::el8 cpe:/a:redhat:multicluster_engine:2.1::el8 cpe:/a:redhat:openshift_distributed_tracing:2.9::el8 |
|
| Vendors & Products |
Redhat openshift Distributed Tracing
|
Mon, 19 Aug 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.1::el8 cpe:/a:redhat:openshift_distributed_tracing:2.9::el8 |
|
| Vendors & Products |
Redhat openshift Distributed Tracing
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-02-13T17:02:46.777Z
Reserved: 2023-07-27T17:05:55.186Z
Link: CVE-2023-39318
Updated: 2024-08-02T18:02:06.918Z
Status : Modified
Published: 2023-09-08T17:15:27.823
Modified: 2024-11-21T08:15:08.737
Link: CVE-2023-39318
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN