CVE-2023-3978
Summary
| CVE | CVE-2023-3978 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-02 20:15:00 UTC |
| Updated | 2023-11-07 04:20:00 UTC |
| Description | Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Golang |
Networking |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| go.dev/cl/514896 |
MISC |
go.dev |
|
| x/net/html: text nodes outside of the HTML namespace improperly rendered · Issue #61615 · golang/go · GitHub |
MISC |
go.dev |
|
| 404 Not Found - Go Packages |
MISC |
pkg.go.dev |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161063 Oracle Enterprise Linux Security Update for podman (ELSA-2023-6474)
- 161175 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2023-6939)
- 161187 Oracle Enterprise Linux Security Update for container-tools:4.0 (ELSA-2023-6938)
- 242335 Red Hat Update for podman security (RHSA-2023:6474)
- 242374 Red Hat OpenShift Container Platform 4.14 Security Update (RHSA-2023:5009)
- 242415 Red Hat Update for container-tools:rhel8 (RHSA-2023:6939)
- 242458 Red Hat Update for container-tools:4.0 (RHSA-2023:6938)
- 242967 Red Hat OpenShift Container Platform 4.14 Security Update (RHSA-2024:0944)
- 285298 Fedora Security Update for caddy (FEDORA-2023-5effef25a3)
- 285300 Fedora Security Update for golang (FEDORA-2023-dc7cceb285)
- 356374 Amazon Linux Security Advisory for amazon-ssm-agent : ALAS2023-2023-373
- 356387 Amazon Linux Security Advisory for nerdctl : ALAS2023-2023-366
- 356428 Amazon Linux Security Advisory for amazon-ssm-agent : ALAS2-2023-2303
- 357082 Amazon Linux Security Advisory for containerd : ALAS2DOCKER-2024-037
- 357087 Amazon Linux Security Advisory for cri-tools : ALAS2-2024-2446
- 357098 Amazon Linux Security Advisory for containerd : ALAS2NITRO-ENCLAVES-2024-037
- 357323 Amazon Linux Security Advisory for containerd : ALAS2ECS-2024-035
- 379641 Alibaba Cloud Linux Security Update for container-tools:rhel8 (ALINUX3-SA-2024:0050)
- 6140018 AWS Bottlerocket Security Update for golang.org/x/net (GHSA-mq67-7rqj-xp39)
- 6140201 AWS Bottlerocket Security Update for golang.org/x/net (GHSA-mq67-7rqj-xp39)
- 770213 Red Hat OpenShift Container Platform 4.14 Security Update (RHSA-2023:5009)
- 770232 Red Hat OpenShift Container Platform 4.14 Security Update (RHSA-2024:0944)
- 907615 Common Base Linux Mariner (CBL-Mariner) Security Update for telegraf (27831-1)
- 941399 AlmaLinux Security Update for podman (ALSA-2023:6474)
- 941444 AlmaLinux Security Update for container-tools:4.0 (ALSA-2023:6938)
- 941481 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2023:6939)
- 995567 GO (Go) Security Update for golang.org/x/net (GHSA-2wrh-6pvc-2jm9)