VDB
RHSA-2023%3A3415
RHSA-2023%3A3415
PUBLISHED
CVSS 7.300000190734863 HIGH
A flaw was found in golang where angle brackets (<>) were not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character could result in the CSS context unexpectedly closing, allowing for the injection of unexpected HMTL if executed with untrusted input.
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | advanced-cluster-security/rhacs-central-db-rhel8@sha256:9b03aca946f78e31e1a4e0536ac5c5871df33ce1d73bde19e62f12513e1e9bfe_ppc64le as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-central-db-rhel8@sha256:9b03aca946f78e31e1a4e0536ac5c5871df33ce1d73bde19e62f12513e1e9bfe_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:04239174dd2fcf854f3ce65b313f114e39b556ddb92e2a5a3fe807e9d315af95_s390x as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-scanner-rhel8@sha256:04239174dd2fcf854f3ce65b313f114e39b556ddb92e2a5a3fe807e9d315af95_s390x, advanced-cluster-security/rhacs-scanner-rhel8@sha256:04239174dd2fcf854f3ce65b313f114e39b556ddb92e2a5a3fe807e9d315af95_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:dbbfc35b869db36a8075e4476fc80d3e5020dd335618e76998c47f6501dd97cc_amd64 as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:dbbfc35b869db36a8075e4476fc80d3e5020dd335618e76998c47f6501dd97cc_amd64 |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:bb2e8930ec4ab4655e79a71b0ff2fbe393599cc93c01505f940f4377a7e59883_ppc64le as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:bb2e8930ec4ab4655e79a71b0ff2fbe393599cc93c01505f940f4377a7e59883_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-central-db-rhel8@sha256:ec389417464ad3fc8d729a1c9b73d7be39949bb7996719b03203b2cc78413376_amd64 as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-central-db-rhel8@sha256:ec389417464ad3fc8d729a1c9b73d7be39949bb7996719b03203b2cc78413376_amd64 |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:21fb603cbe41821c395b20adf95321b03a93a9eddfaa82f6abd87d181a974c39_amd64 as a component of RHACS 4.0 for RHEL 8 | *, advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:21fb603cbe41821c395b20adf95321b03a93a9eddfaa82f6abd87d181a974c39_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:172e8395fd0a6515bda05645536fa9f84d80c11c3ab85643d2910db60faf40d6_s390x as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:172e8395fd0a6515bda05645536fa9f84d80c11c3ab85643d2910db60faf40d6_s390x |
| Red Hat | advanced-cluster-security/rhacs-main-rhel8@sha256:0efd32861819fac6fcdb611070c30efbbce1d34eaa975c48f793fd7b260d822c_s390x as a component of RHACS 4.0 for RHEL 8 | *, * |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:bb2e8930ec4ab4655e79a71b0ff2fbe393599cc93c01505f940f4377a7e59883_ppc64le as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:bb2e8930ec4ab4655e79a71b0ff2fbe393599cc93c01505f940f4377a7e59883_ppc64le, advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:bb2e8930ec4ab4655e79a71b0ff2fbe393599cc93c01505f940f4377a7e59883_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:f6f5c1b86e199af5beaf1820c298f21fddab68cd6adb401d674a4e1724ec457f_amd64 as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:f6f5c1b86e199af5beaf1820c298f21fddab68cd6adb401d674a4e1724ec457f_amd64 |
| Red Hat | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:64a11074a4333a50079ac98cf842c2feaa4226d5f964c171a342d252f42e4438_s390x as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-collector-slim-rhel8@sha256:64a11074a4333a50079ac98cf842c2feaa4226d5f964c171a342d252f42e4438_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:28dda88671e98ef6c88c3bb3989021fc3650247c10514794de678f0f3822cede_ppc64le as a component of RHACS 4.0 for RHEL 8 | *, advanced-cluster-security/rhacs-scanner-rhel8@sha256:28dda88671e98ef6c88c3bb3989021fc3650247c10514794de678f0f3822cede_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:dc2bcdfa399edb9855c77f5e9f4c6baeae162234fbf136a129ff60fc1805927a_amd64 as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-scanner-rhel8@sha256:dc2bcdfa399edb9855c77f5e9f4c6baeae162234fbf136a129ff60fc1805927a_amd64, * |
| Red Hat | advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:dbbfc35b869db36a8075e4476fc80d3e5020dd335618e76998c47f6501dd97cc_amd64 as a component of RHACS 4.0 for RHEL 8 | *, * |
| Red Hat | advanced-cluster-security/rhacs-operator-bundle@sha256:40407c0e28258f463e0e50c2e5d00570e2558c7b34da6c9cb44939c2dd7efba9_s390x as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-operator-bundle@sha256:40407c0e28258f463e0e50c2e5d00570e2558c7b34da6c9cb44939c2dd7efba9_s390x |
| Red Hat | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:4fe44befb2fbf3e945de83ae9b5a39d85627d62e986abc9a8134a2c108e8eb08_s390x as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:4fe44befb2fbf3e945de83ae9b5a39d85627d62e986abc9a8134a2c108e8eb08_s390x, advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:4fe44befb2fbf3e945de83ae9b5a39d85627d62e986abc9a8134a2c108e8eb08_s390x |
| Red Hat | advanced-cluster-security/rhacs-collector-rhel8@sha256:d67c6b1abce362da0b158c4fafb6bae1ca5070ac32ebfc9aa16be475ba223690_ppc64le as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-collector-rhel8@sha256:d67c6b1abce362da0b158c4fafb6bae1ca5070ac32ebfc9aa16be475ba223690_ppc64le |
| Red Hat | advanced-cluster-security/rhacs-rhel8-operator@sha256:44cfa2761d81d4252299f136c244a7c80c674465d718a38d11e0422e3c5414a5_amd64 as a component of RHACS 4.0 for RHEL 8 | advanced-cluster-security/rhacs-rhel8-operator@sha256:44cfa2761d81d4252299f136c244a7c80c674465d718a38d11e0422e3c5414a5_amd64 |
| Red Hat | advanced-cluster-security/rhacs-scanner-rhel8@sha256:04239174dd2fcf854f3ce65b313f114e39b556ddb92e2a5a3fe807e9d315af95_s390x as a component of RHACS 4.0 for RHEL 8 | * |
| Red Hat | advanced-cluster-security/rhacs-operator-bundle@sha256:7e08088dc72f668b36f67b18c2ec2cbdb621d547f00699b3fb8d6de0ccbaec57_amd64 as a component of RHACS 4.0 for RHEL 8 | * |
…and 46 more
Timeline
- May 31, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 29, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:3415 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://docs.openshift.com/acs/4.0/release_notes/40-release-notes.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2196026 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2196027 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2196029 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3415.json advisory
- https://access.redhat.com/security/cve/CVE-2023-24539 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-24539 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-24539 advisory
- https://github.com/golang/go/issues/59720 advisory
- https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU advisory
- https://access.redhat.com/security/cve/CVE-2023-24540 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-24540 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-24540 advisory
- https://go.dev/issue/59721 advisory
- https://access.redhat.com/security/cve/CVE-2023-29400 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-29400 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-29400 advisory
- https://go.dev/issue/59722 advisory