Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7v2-7v9m-q9j4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

EPSS

Процентиль: 41%
0.00187
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-115

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVSS3: 5.6
redhat
около 5 лет назад

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVSS3: 9.8
nvd
около 5 лет назад

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVSS3: 5.6
msrc
около 4 лет назад

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVSS3: 9.8
debian
около 5 лет назад

The encoding/xml package in Go (all versions) does not correctly prese ...

EPSS

Процентиль: 41%
0.00187
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-115