Lucene search

K
redhatcveRedhat.comRH:CVE-2023-39319
HistorySep 13, 2023 - 6:54 a.m.

CVE-2023-39319

2023-09-1306:54:21
redhat.com
access.redhat.com
16
golang
html/template
script context
termination
improper handling
cve-2023-39319
flaw

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

42.4%

A flaw was found in Golang. The html/template package did not apply the proper rules for handling occurrences of " contexts. This issue may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped.

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

42.4%