Описание
Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.
A flaw was found in the html/template package. This vulnerability arises from improper tracking of context and brace depth within JavaScript (JS) template literals. A remote attacker could exploit these issues to cause content to be incorrectly or improperly escaped, leading to Cross-Site Scripting (XSS) vulnerabilities. This could allow an attacker to inject malicious scripts into web pages viewed by other users.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Assisted Installer for Red Hat OpenShift Container Platform 2 | redhat-user-workloads/appliance | Fix deferred | ||
| Builds for Red Hat OpenShift | redhat-user-workloads/openshift-builds-waiter-1-6 | Fix deferred | ||
| Builds for Red Hat OpenShift | redhat-user-workloads/openshift-builds-waiter-1-7 | Fix deferred | ||
| cert-manager Operator for Red Hat OpenShift | redhat-user-workloads/jetstack-cert-manager-1-17 | Fix deferred | ||
| cert-manager Operator for Red Hat OpenShift | redhat-user-workloads/jetstack-cert-manager-1-18 | Fix deferred | ||
| Compliance Operator | redhat-user-workloads/compliance-operator-bundle-release | Fix deferred | ||
| Confidential Compute Attestation | redhat-user-workloads/osc-caa | Fix deferred | ||
| Confidential Compute Attestation | redhat-user-workloads/trustee-operator | Fix deferred | ||
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Fix deferred | ||
| Custom Metric Autoscaler operator for Red Hat Openshift | redhat-user-workloads/keda-adapter | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.
Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.
Context was not properly tracked across template branches for JS templ ...
Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.
EPSS
5.4 Medium
CVSS3