Lucene search

K
osvGoogleOSV:CVE-2020-29510
HistoryDec 14, 2020 - 8:15 p.m.

CVE-2020-29510

2020-12-1420:15:13
Google
osv.dev
6

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.1%

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.1%