UBUNTU-CVE-2024-24785
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-24785
UBUNTU-CVE-2024-24785
Summary:
Details: If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.
References: https://ubuntu.com/security/CVE-2024-24785, https://github.com/golang/go/issues/65697, https://github.com/golang/go/commit/056b0edcb8c152152021eebf4cf42adbfbe77992, https://github.com/golang/go/commit/3643147a29352ca2894fd5d0d2069bc4b4335a7e, https://go.dev/issue/65697, https://go.dev/cl/564196, https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg, https://pkg.go.dev/vuln/GO-2024-2610, https://www.cve.org/CVERecord?id=CVE-2024-24785, https://ubuntu.com/security/notices/USN-6886-1, https://ubuntu.com/security/notices/USN-7061-1, https://ubuntu.com/security/notices/USN-7109-1
Affected packages
Package
Name: golang-1.10
Purl: pkg:deb/ubuntu/golang-1.10?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
