Описание
If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.
A flaw was found in Go's html/template standard library package. If errors returned from MarshalJSON methods contain user-controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing subsequent actions to inject unexpected content into templates.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Not affected | ||
Cost Management Metrics Operator | costmanagement/costmanagement-metrics-rhel8-operator | Affected | ||
Logical Volume Manager Storage | lvms4/topolvm-rhel9 | Not affected | ||
Migration Toolkit for Applications 6 | mta/mta-hub-rhel8 | Will not fix | ||
Migration Toolkit for Applications 7 | mta/mta-cli-rhel9 | Not affected | ||
Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-api-rhel9 | Affected | ||
Multicluster Engine for Kubernetes | multicluster-engine/hive-rhel8 | Will not fix | ||
Node Maintenance Operator | workload-availability/node-maintenance-rhel8-operator | Will not fix | ||
OpenShift Developer Tools and Services | helm | Affected | ||
OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.
If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.
If errors returned from MarshalJSON methods contain user controlled da ...
If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.
Уязвимость пакета html/template языка программирования Go, связанная с отсутствием проверки входных значений, позволяющая нарушителю вводить произвольный контент в шаблоны
EPSS
6.5 Medium
CVSS3