CVE-2023-24540

Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
GoCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
VendorProductVersion
golanggo
𝑥
< 1.19.9
golanggo
1.20.0 ≤
𝑥
< 1.20.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
vulnerable
bookworm
no-dsa
buster
postponed
golang-1.19
bookworm
vulnerable
bullseye
no-dsa
buster
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-1.19
lunar
Fixed 1.19.8-1ubuntu0.1
released
kinetic
Fixed 1.19.2-1ubuntu1.1
released
jammy
dne
focal
dne
bionic
dne
xenial
ignored
trusty
ignored
golang-1.20
lunar
Fixed 1.20.3-1ubuntu0.1
released
kinetic
dne
jammy
not-affected
focal
not-affected
bionic
dne
xenial
ignored
trusty
ignored