CVE-2023-39318

Name
CVE-2023-39318
Description
The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ
MISC https://pkg.go.dev/vuln/GO-2023-2041
MISC https://go.dev/cl/526156
MISC https://go.dev/issue/62196
Third Party Advisory https://security.netapp.com/advisory/ntap-20231020-0009/
https://security.gentoo.org/glsa/202311-09

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* go >= 1.21.0 < 1.21.1
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* go >= None < 1.20.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status