contexts. This may cause the template parser to improperly interpret the contents of

CVE-2023-39318 : Detail

CVE-2023-39318

6.1
/
Medium
Cross-site Scripting
A03-Injection
0.25%V3
Network
2023-09-08
16h13 +00:00
2025-02-13
17h02 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Improper handling of HTML-like comments in script contexts in html/template

The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in

Products Mentioned

Configuraton 0

Golang>>Go >> Version To (excluding) 1.20.8

Golang>>Go >> Version From (including) 1.21.0 To (excluding) 1.21.1

References

https://go.dev/issue/62196
Tags : Issue Tracking