The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Golang
Subscribe
|
Go
Subscribe
|
|
Redhat
Subscribe
|
Acm
Subscribe
Enterprise Linux
Subscribe
Migration Toolkit Virtualization
Subscribe
Multicluster Engine
Subscribe
Network Observ Optr
Subscribe
Openshift
Subscribe
Openshift Api Data Protection
Subscribe
Openshift Data Foundation
Subscribe
Openshift Distributed Tracing
Subscribe
Openshift Secondary Scheduler
Subscribe
Openstack
Subscribe
Rhmt
Subscribe
Run Once Duration Override Operator
Subscribe
Service Interconnect
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43051 | The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack. |
Ubuntu USN |
USN-6574-1 | Go vulnerabilities |
Ubuntu USN |
USN-7061-1 | Go vulnerabilities |
Ubuntu USN |
USN-7109-1 | Go vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Distributed Tracing
|
|
| CPEs | cpe:/a:redhat:acm:2.6::el8 cpe:/a:redhat:multicluster_engine:2.1::el8 cpe:/a:redhat:openshift_distributed_tracing:2.9::el8 |
|
| Vendors & Products |
Redhat openshift Distributed Tracing
|
Mon, 19 Aug 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.1::el8 cpe:/a:redhat:openshift_distributed_tracing:2.9::el8 |
|
| Vendors & Products |
Redhat openshift Distributed Tracing
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-02-13T17:02:47.366Z
Reserved: 2023-07-27T17:05:55.186Z
Link: CVE-2023-39319
Updated: 2024-08-02T18:02:06.746Z
Status : Modified
Published: 2023-09-08T17:15:27.910
Modified: 2024-11-21T08:15:08.890
Link: CVE-2023-39319
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN