CVE-2023-24539

Aliases:GO-2023-1751BIT-golang-2023-24539DEBIAN-CVE-2023-24539CGA-22cg-36j7-rf3hCGA-3jrr-wx67-454fCGA-5fhx-8qj3-q7g9CGA-7cw7-r5rv-c89xCGA-7gwc-x327-f3wgCGA-7j2q-p2fx-6f6cCGA-93jx-42mv-mp5pCGA-9fvq-8727-r23cCGA-9vpw-hpwc-286fCGA-g92g-53v3-phx8CGA-ggx7-257c-vrm5CGA-hh23-q3rw-j86cCGA-j3hv-7fc6-627gCGA-jg6j-62x8-5pqrCGA-pfp2-hf22-9vq5CGA-q6vh-685c-2p6jCGA-qv4p-476w-9qwpCGA-r9x3-845f-g375CGA-rmqg-5cjj-jmp8CGA-wm4x-99h5-m3xjCGA-5jj6-9hh9-3766CGA-w7vq-g7pj-jw66
Modified
Published: 11 May 2023, 15:29
Last modified:24 Jan 2025, 16:41

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.3 HIGH
v3.1 (cve.org)
EPSS Score
1.04% LOW
1% probability +0.97%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 May 2023, 15:29
Published
Vulnerability first disclosed
24 Jan 2025, 16:41
Last Modified
Vulnerability information updated

Description

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.

CVSS Metrics

  • v3.1HIGHScore: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS Trends

Current EPSS score: 1.04% Percentile: 62%

Techniques & Countermeasures

  • CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

  • CWE-94Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Affected Systems

  • chainguardgo-1.20

    < 1.20.4-r0

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    all

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • wolfigo-1.20

    < 1.20.4-r0

  • wolfikatib-earlystopping

    < 0.19.0-r31

  • wolfikatib-suggestion-goptuna-compat

    all

  • wolfikatib-suggestion-hyperband

    < 0.19.0-r31

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • wolfikatib-suggestion-nas-darts

    < 0.19.0-r31

  • wolfikatib-suggestion-nas-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-optuna-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-pbt-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-skopt-enas

    < 0.19.0-r31

  • wolfikatib-tfevent-metricscollector

    < 0.19.0-r31

  • debiangolang-1.15

    all

  • debiangolang-1.19

    all

  • go standard libraryhtml/template

    < 1.19.9 | ≥ 1.20.0-0, < 1.20.4

  • golanggo

    < 1.19.9 | ≥ 1.20.0, < 1.20.4

  • Gostdlib

    ≥ 1.20.0-0, < 1.20.4

References (9)