VDB
DEBIAN-CVE-2023-3978
DEBIAN-CVE-2023-3978
PUBLISHED
CVSS 6.099999904632568 MEDIUM
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | golang-golang-x-net | 0, 0, 0 |
| Debian:11 | golang-golang-x-net | 0.0+git20220225.27dd868, 0.0+git20211209.491a49a, 0.0+git20211209.491a49a |
| Debian:12 | golang-golang-x-net | 0.17.0+dfsg, 0.14.0-1, 0.15.0-1 |
| Debian:14 | golang-golang-x-net | 0, 0, 0 |
Exploit Intelligence
- scan.openvex.json (github-poc)
Timeline
- Aug 2, 2023 CVE Published
- Apr 28, 2026 CVE Updated