CVE-2023-39318
Dashboard / Vulnerabilities / CVE-2023-39318
CVE-2023-39318
Summary: Improper handling of HTML-like comments in script contexts in html/template
Details: The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.
References: https://go.dev/cl/526156, https://go.dev/issue/62196, https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ, https://pkg.go.dev, https://pkg.go.dev/vuln/GO-2023-2041, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39318.json, https://nvd.nist.gov/vuln/detail/CVE-2023-39318, https://security.gentoo.org/glsa/202311-09, https://security.netapp.com/advisory/ntap-20231020-0009/
Affected packages
Package
Name:
Purl:
