CVE-2023-29400

Aliases:GO-2023-1753BIT-golang-2023-29400DEBIAN-CVE-2023-29400CGA-2rc4-588j-mp3qCGA-4946-hhxf-vrhfCGA-5p8g-f2w6-2jjqCGA-685m-v73m-mfjvCGA-7m9f-jg7x-92c5CGA-8h37-vcx3-4w4mCGA-93q9-pwgv-j2m3CGA-fxrm-cc5r-hr2vCGA-gjm4-93jq-ggx2CGA-h336-m3gw-wc68CGA-h9gf-qx8w-rhh3CGA-p584-w2mh-9h2mCGA-p6jf-rxhx-q6vxCGA-q6f9-264m-c2xxCGA-r5xf-pm56-2wg7CGA-r8gm-hq9j-83gvCGA-v653-5682-4pgcCGA-wvq3-r3gc-6xmgCGA-x5xw-98fv-vqw8CGA-xm83-rj6q-qv83CGA-3cw5-gf9m-xpgqCGA-7h9r-hwj7-8m79
Modified
Published: 11 May 2023, 15:29
Last modified:24 Jan 2025, 16:47

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.3 HIGH
v3.1 (cve.org)
EPSS Score
1.04% LOW
1% probability +0.99%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 May 2023, 15:29
Published
Vulnerability first disclosed
24 Jan 2025, 16:47
Last Modified
Vulnerability information updated

Description

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

CVSS Metrics

  • v3.1HIGHScore: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS Trends

Current EPSS score: 1.04% Percentile: 62%

Techniques & Countermeasures

  • CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

  • CWE-94Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Affected Systems

  • chainguardgo-1.20

    < 1.20.4-r0

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • wolfigo-1.20

    < 1.20.4-r0

  • wolfikatib-earlystopping

    < 0.19.0-r31

  • wolfikatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • wolfikatib-suggestion-hyperband

    < 0.19.0-r31

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • wolfikatib-suggestion-nas-darts

    < 0.19.0-r31

  • wolfikatib-suggestion-nas-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-optuna-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-pbt-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-skopt-enas

    < 0.19.0-r31

  • wolfikatib-tfevent-metricscollector

    < 0.19.0-r31

  • debiangolang-1.15

    all

  • debiangolang-1.19

    all

  • go standard libraryhtml/template

    < 1.19.9 | ≥ 1.20.0-0, < 1.20.4

  • golanggo

    < 1.19.9 | ≥ 1.20.0, < 1.20.4

  • Gostdlib

    ≥ 1.20.0-0, < 1.20.4

References (9)