Name
CVE-2023-29400
Description
Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.
Published Date
Updated Date
Workaround
-
Advisories
https://go.dev/issue/59722Issue Tracking
https://pkg.go.dev/vuln/GO-2023-1753Vendor Advisory
https://go.dev/issue/59722Issue Tracking
https://pkg.go.dev/vuln/GO-2023-1753Vendor Advisory
Analysis#
Vulnerability Ratings#
7.3
CVSSv31
7.3
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Not Affected
openwrt
master
1.26.4-r1
Not Affected
openwrt
openwrt-25.12
1.24.13-r1
Not Affected
openwrt
openwrt-25.12
1.26.4-r1
Not Affected
yocto
master
1.26.4
Not Affected
yocto
master
1.26.4
Not Affected
yocto
scarthgap
1.22.12
Not Affected
yocto
scarthgap
1.22.12
Not Affected