VDB
BDU%3A2023-03470
BDU%3A2023-03470
PUBLISHED
CVSS 7.5 HIGH
Уязвимость языка программирования Go, связанная с ошибками при обработке специальных символов "<>" в контексте CSS, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», The Go Project | Red Hat Enterprise Linux, openSUSE Tumbleweed, Red Hat Storage, Red Hat Quay, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), OpenSUSE Leap, SUSE Linux Enterprise Server for SAP Applications, Red Hat Openshift Data Foundation, Red Hat OpenShift GitOps, Suse Linux Enterprise Server, Red Hat OpenShift Container Platform, Suse Linux Enterprise Desktop, Red Hat OpenStack Platform, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise High Performance Computing, SUSE Enterprise Storage, SUSE Linux Enterprise Module for Development Tools, Red Hat Web Terminal, SUSE Linux Enterprise Real Time, Red Hat OpenShift Data Science (RHODS), Red Hat OpenShift Virtualization, Go, Red Hat Migration Toolkit for Containers, Red Hat OpenShift Dev Spaces, Self Node Remediation, OpenShift Pipelines, SUSE Liberty Linux, Red Hat OpenShift distributed tracing, Red Hat Ansible Automation Platform, Migration Toolkit for Virtualization, multicluster engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes, Red Hat Service Interconnect |
Timeline
- Jun 29, 2023 CVE Published
- Dec 5, 2024 CVE Updated
References
- https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU url
- https://go.dev/issue/59720 url
- https://www.rapid7.com/db/vulnerabilities/suse-cve-2023-24539/ url
- https://pkg.go.dev/vuln/GO-2023-1751 url
- https://go.dev/cl/491615 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://www.suse.com/security/cve/CVE-2023-24539.html url
- https://access.redhat.com/security/cve/cve-2023-24539 url
- https://security-tracker.debian.org/tracker/CVE-2023-24539 url