Server side template injection In golang-1.15
Description
Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
debian 12 | - | ||
go | 1.19.9 | ||
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel9 | 1:1.31.3-1.el9 | ||
rpm rhel8 | - | - | |
rpm rhel9 | 1:1.3.0-4.el9 | ||
rpm rhel8 | 0:1.19.9-1.module+el8.8.0+18857+fca43658 | ||
rpm rhel9 | 0:1.19.9-2.el9_2 |
1-10 of 15
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.