Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9hr-fvm9-7c49

Опубликовано: 11 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

EPSS

Процентиль: 59%
0.01029
Низкий

7.3 High

CVSS3

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 3 лет назад

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

CVSS3: 7.3
redhat
около 3 лет назад

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

CVSS3: 7.3
nvd
около 3 лет назад

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

CVSS3: 7.3
msrc
10 месяцев назад

Improper handling of empty HTML attributes in html/template

CVSS3: 7.3
debian
около 3 лет назад

Templates containing actions in unquoted HTML attributes (e.g. "attr={ ...

EPSS

Процентиль: 59%
0.01029
Низкий

7.3 High

CVSS3

Дефекты

CWE-74
CWE-94