CVE-2024-55601

Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks. Those whoa re impacted are Hugo users who do not trust their Markdown content files and are using one or more of these templates: `_default/_markup/render-link.html` from `v0.123.0`; `_default/_markup/render-image.html` from `v0.123.0`; `_default/_markup/render-table.html` from `v0.134.0`; and/or `shortcodes/youtube.html` from `v0.125.0`. This issue is patched in v0.139.4. As a workaround, one may replace an affected component with user defined templates or disable the internal templates.
CVSS

No CVSS.

Configurations

No configuration.

History

09 Dec 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-09 22:15

Updated : 2024-12-09 22:15


NVD link : CVE-2024-55601

Mitre link : CVE-2024-55601

CVE.ORG link : CVE-2024-55601


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')