Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p6mv-vmpw-j23r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

EPSS

Процентиль: 32%
0.00122
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVSS3: 5.6
redhat
около 5 лет назад

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVSS3: 9.8
nvd
около 5 лет назад

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

CVSS3: 9.8
debian
около 5 лет назад

The encoding/xml package in Go versions 1.15 and earlier does not corr ...

EPSS

Процентиль: 32%
0.00122
Низкий