Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26

Количество 26

fstec логотип

BDU:2024-01979

больше 3 лет назад

Уязвимость пакета golang операционной системы Debian GNU/Linux, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20241017-01

почти 2 года назад

Множественные уязвимости golang

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20241203-15

почти 2 года назад

Множественные уязвимости filebeat

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2023-1598

больше 3 лет назад

ALT-PU-2023-1598: package `golang` update to version 1.19.8-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2023-1575

больше 3 лет назад

ALT-PU-2023-1575: package `golang` update to version 1.20.3-alt1

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-24538

больше 3 лет назад

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmplliti...

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2023-24538

больше 3 лет назад

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmplliti...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-24538

больше 3 лет назад

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinte

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2023-24538

около 1 года назад

Backticks not treated as string delimiters in html/template

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-24538

больше 3 лет назад

Templates do not properly consider backticks (`) as Javascript string ...

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20240418-06

больше 2 лет назад

Множественные уязвимости buildah

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2023-4736

около 3 лет назад

ALT-PU-2023-4736: package `golang` update to version 1.20.7-alt1

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v4m2-x4rp-hv22

больше 3 лет назад

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmplliti...

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1792-1

больше 3 лет назад

Security update for go1.19

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1791-1

больше 3 лет назад

Security update for go1.20

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2127-1

больше 3 лет назад

Security update for go1.19

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2105-2

больше 3 лет назад

Security update for go1.20

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2105-1

больше 3 лет назад

Security update for go1.20

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6402

почти 3 года назад

ELSA-2023-6402: containernetworking-plugins security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6473

почти 3 года назад

ELSA-2023-6473: buildah security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-01979

Уязвимость пакета golang операционной системы Debian GNU/Linux, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
redos логотип
ROS-20241017-01

Множественные уязвимости golang

CVSS3: 9.8
почти 2 года назад
redos логотип
ROS-20241203-15

Множественные уязвимости filebeat

CVSS3: 9.8
почти 2 года назад
altlinux логотип
ALT-PU-2023-1598

ALT-PU-2023-1598: package `golang` update to version 1.19.8-alt1

CVSS3: 9.8
больше 3 лет назад
altlinux логотип
ALT-PU-2023-1575

ALT-PU-2023-1575: package `golang` update to version 1.20.3-alt1

CVSS3: 9.8
больше 3 лет назад
ubuntu логотип
CVE-2023-24538

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmplliti...

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-24538

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmplliti...

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
nvd логотип
CVE-2023-24538

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinte

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-24538

Backticks not treated as string delimiters in html/template

CVSS3: 9.8
2%
Низкий
около 1 года назад
debian логотип
CVE-2023-24538

Templates do not properly consider backticks (`) as Javascript string ...

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
redos логотип
ROS-20240418-06

Множественные уязвимости buildah

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2023-4736

ALT-PU-2023-4736: package `golang` update to version 1.20.7-alt1

CVSS3: 9.8
около 3 лет назад
github логотип
GHSA-v4m2-x4rp-hv22

Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. "var a = {{.}}"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmplliti...

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:1792-1

Security update for go1.19

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:1791-1

Security update for go1.20

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2127-1

Security update for go1.19

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2105-2

Security update for go1.20

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2105-1

Security update for go1.20

больше 3 лет назад
oracle-oval логотип
ELSA-2023-6402

ELSA-2023-6402: containernetworking-plugins security and bug fix update (MODERATE)

почти 3 года назад
oracle-oval логотип
ELSA-2023-6473

ELSA-2023-6473: buildah security update (MODERATE)

почти 3 года назад

Уязвимостей на страницу