Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9hr-fvm9-7c49

Опубликовано: 11 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

EPSS

Процентиль: 15%
0.00048
Низкий

7.3 High

CVSS3

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 2 лет назад

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

CVSS3: 7.3
redhat
больше 2 лет назад

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

CVSS3: 7.3
nvd
больше 2 лет назад

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

CVSS3: 7.3
msrc
около 2 месяцев назад

Improper handling of empty HTML attributes in html/template

CVSS3: 7.3
debian
больше 2 лет назад

Templates containing actions in unquoted HTML attributes (e.g. "attr={ ...

EPSS

Процентиль: 15%
0.00048
Низкий

7.3 High

CVSS3

Дефекты

CWE-74
CWE-94