ZeroHour

CVE-2023-29400

CVSS 3.1
7.3 high
EPSS
1%p62
Published
()
Modified
Description

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

Vendors
golang
Products
go
Weakness
CWE-74, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.