QID 982550
QID 982550: Go (go) Security Update for github.com/microcosm-cc/bluemonday (GHSA-3x58-xr87-2fcj)
bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a protection mechanism against the "script" string.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3x58-xr87-2fcj for updates pertaining to this vulnerability.
Vendor References
- GHSA-3x58-xr87-2fcj -
github.com/advisories/GHSA-3x58-xr87-2fcj
CVEs related to QID 982550
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3x58-xr87-2fcj | github.com/microcosm-cc/bluemonday |
|