Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-24539

Опубликовано: 20 апр. 2023
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

A flaw was found in golang where angle brackets (<>) were not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character could result in the CSS context unexpectedly closing, allowing for the injection of unexpected HMTL if executed with untrusted input.

Отчет

For Red Hat Enterprise Linux,

  • Conmon uses go in unit testing, but not functionally in the package. Go is used only in test files, not in the actual code. Thus, conmon is not affected.
  • The Go templates in Grafana do not contain any javascript. Thus, it is not affected.
  • Ignition does not make use of html/template. In Red Hat Advanced Cluster Management for Kubernetes (RHACM), the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable golang html/templates to authenticated users only, therefore, the impact is low.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel8-operatorAffected
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and ServicesodoWill not fix
OpenShift Pipelinesopenshift-pipelines-clientWill not fix
OpenShift Service Mesh 2openshift-golang-builder-containerNot affected
Red Hat 3scale API Management Platform 23scale-operator-containerAffected
Red Hat AMQ Broker 7amq-broker-rhel8-operator-containerAffected
Red Hat Application Interconnect 1.0skupper-cliAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-176
https://bugzilla.redhat.com/show_bug.cgi?id=2196026golang: html/template: improper sanitization of CSS values

EPSS

Процентиль: 21%
0.00065
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 2 лет назад

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

CVSS3: 7.3
nvd
около 2 лет назад

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

CVSS3: 7.3
debian
около 2 лет назад

Angle brackets (<>) are not considered dangerous characters when inser ...

CVSS3: 7.3
github
около 2 лет назад

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

CVSS3: 7.3
fstec
около 2 лет назад

Уязвимость языка программирования Go, связанная с ошибками при обработке специальных символов &quot;&lt;&gt;&quot; в контексте CSS, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 21%
0.00065
Низкий

7.3 High

CVSS3

Уязвимость CVE-2023-24539