vulnerability
Red Hat OpenShift: CVE-2023-39318: golang: html/template: improper handling of HTML-like comments within script contexts
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:N/AC:M/Au:N/C:P/I:P/A:N) | 2023-09-08 | 2023-11-01 | 2025-04-11 |
Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
2023-09-08
Added
2023-11-01
Modified
2025-04-11
Description
The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in
Solution(s)
linuxrpm-upgrade-buildahlinuxrpm-upgrade-containernetworking-pluginslinuxrpm-upgrade-microshiftlinuxrpm-upgrade-openshift-clientslinuxrpm-upgrade-podmanlinuxrpm-upgrade-runclinuxrpm-upgrade-skopeo
References
- CVE-2023-39318
- https://attackerkb.com/topics/CVE-2023-39318
- REDHAT-RHSA-2023:5008
- REDHAT-RHSA-2023:5009
- REDHAT-RHSA-2023:5947
- REDHAT-RHSA-2023:5974
- REDHAT-RHSA-2023:6085
- REDHAT-RHSA-2023:6115
- REDHAT-RHSA-2023:6119
- REDHAT-RHSA-2023:6122
- REDHAT-RHSA-2023:6145
- REDHAT-RHSA-2023:6148
- REDHAT-RHSA-2023:6154
- REDHAT-RHSA-2023:6161
- REDHAT-RHSA-2023:6200
- REDHAT-RHSA-2023:6202
- REDHAT-RHSA-2023:6840
- REDHAT-RHSA-2023:7762
- REDHAT-RHSA-2023:7764
- REDHAT-RHSA-2023:7765
- REDHAT-RHSA-2023:7766
- REDHAT-RHSA-2024:0121
- REDHAT-RHSA-2024:1383
- REDHAT-RHSA-2024:1901
- REDHAT-RHSA-2024:2160
- REDHAT-RHSA-2024:2988
- REDHAT-RHSA-2024:3352
- REDHAT-RHSA-2024:3467

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.