CVE-2020-29510

Name
CVE-2020-29510
Description
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-directives.md
Third Party Advisory https://security.netapp.com/advisory/ntap-20210129-0006/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* go >= None <= 1.15

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
go edge-community 1.15-r0 None possibly vulnerable
go edge-community 1.14.5-r0 None possibly vulnerable
go edge-community 1.13.7-r0 None possibly vulnerable
go edge-community 1.13.2-r0 None possibly vulnerable
go edge-community 1.13.1-r0 None possibly vulnerable
go edge-community 1.12.8-r0 None possibly vulnerable
go edge-community 1.11.5-r0 None possibly vulnerable
go edge-community 1.9.4-r0 None possibly vulnerable
go 3.22-community 1.15-r0 None possibly vulnerable
go 3.22-community 1.14.5-r0 None possibly vulnerable
go 3.22-community 1.13.7-r0 None possibly vulnerable
go 3.22-community 1.13.2-r0 None possibly vulnerable
go 3.22-community 1.13.1-r0 None possibly vulnerable
go 3.22-community 1.12.8-r0 None possibly vulnerable
go 3.22-community 1.11.5-r0 None possibly vulnerable
go 3.22-community 1.9.4-r0 None possibly vulnerable