Описание
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
Ссылки
- Patch
- Issue TrackingPatchVendor Advisory
- Issue TrackingPatchVendor Advisory
- Patch
- Issue TrackingPatchVendor Advisory
- Issue TrackingPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.13.0 (исключая)
cpe:2.3:a:golang:networking:*:*:*:*:*:go:*:*
EPSS
Процентиль: 24%
0.0008
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
ubuntu
около 2 лет назад
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
CVSS3: 6.1
redhat
около 2 лет назад
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
CVSS3: 6.1
debian
около 2 лет назад
Text nodes not in the HTML namespace are incorrectly literally rendere ...
EPSS
Процентиль: 24%
0.0008
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79