CVE-2023-39319

The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

25 Nov 2023, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-08 17:15

Updated : 2024-02-05 00:01


NVD link : CVE-2023-39319

Mitre link : CVE-2023-39319

CVE.ORG link : CVE-2023-39319


JSON object : View

Products Affected

golang

  • go
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')