CVE-2023-24540
Last modified
CVE-2023-24540 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Golang | Go | < 1.19.9 |
| Golang | Go | >= 1.20.0, < 1.20.4 |
References
- https://go.dev/issue/59721Issue Tracking, Patch
- https://groups.google.com/g/golang-announce/c/MEb0UyuSMsUMailing List, Release Notes
- https://pkg.go.dev/vuln/GO-2023-1752Vendor Advisory
- https://go.dev/issue/59721Issue Tracking, Patch
- https://groups.google.com/g/golang-announce/c/MEb0UyuSMsUMailing List, Release Notes
- https://pkg.go.dev/vuln/GO-2023-1752Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-24540?
How severe is CVE-2023-24540?
How do I fix CVE-2023-24540?
Are you affected by CVE-2023-24540?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
