Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv93-wvcp-7m7r

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

golang.org/x/net/html Improper Validation of Array Index vulnerability

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.

Пакеты

Наименование

golang.org/x/net

go
Затронутые версииВерсия исправления

< 0.0.0-20190125002852-4b62a64f59f7

0.0.0-20190125002852-4b62a64f59f7

EPSS

Процентиль: 77%
0.01025
Низкий

7.5 High

CVSS3

Дефекты

CWE-129

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.

CVSS3: 5.3
redhat
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.

CVSS3: 7.5
nvd
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.

CVSS3: 7.5
debian
больше 7 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles ...

EPSS

Процентиль: 77%
0.01025
Низкий

7.5 High

CVSS3

Дефекты

CWE-129