VDB
RHSA-2023%3A4289
RHSA-2023%3A4289
PUBLISHED
CVSS 8.100000381469727 HIGH
A flaw was found in golang, where not all valid JavaScript white-space characters were considered white space. Due to this issue, templates containing white-space characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:dc97222cbf83ce3e372921303e5ee711eea13fa76b36c8f0ba78200a657fe03a_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:dc97222cbf83ce3e372921303e5ee711eea13fa76b36c8f0ba78200a657fe03a_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:dc97222cbf83ce3e372921303e5ee711eea13fa76b36c8f0ba78200a657fe03a_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:dc97222cbf83ce3e372921303e5ee711eea13fa76b36c8f0ba78200a657fe03a_amd64 |
| Red Hat | oadp/oadp-velero-rhel8@sha256:a0f5d406010ba1161572c009e9d3dd62b36124bf57cbc29edff39ac57f1035bb_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-rhel8@sha256:a0f5d406010ba1161572c009e9d3dd62b36124bf57cbc29edff39ac57f1035bb_amd64 |
| Red Hat | oadp/oadp-operator-bundle@sha256:7ac193a2157e5519f5a5e6908d7378a6c231bc4221b350f9ecd908f86866edf8_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-operator-bundle@sha256:7ac193a2157e5519f5a5e6908d7378a6c231bc4221b350f9ecd908f86866edf8_amd64 |
| Red Hat | oadp/oadp-rhel8-operator@sha256:c93d727f3244175c409e7e23301152519a4ac4a6cdfba8107b99f622f0a394de_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-rhel8-operator@sha256:c93d727f3244175c409e7e23301152519a4ac4a6cdfba8107b99f622f0a394de_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:34c535174f0c67b85343d2dedc698c4909d212581bccf4004583916d65c079a0_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:34c535174f0c67b85343d2dedc698c4909d212581bccf4004583916d65c079a0_amd64 |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:b391390d15088e8afd3297e0dbc1ca6ab6e54ff6a61c7e28b2fe7f8f6777c651_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:b391390d15088e8afd3297e0dbc1ca6ab6e54ff6a61c7e28b2fe7f8f6777c651_amd64 |
| Red Hat | oadp/oadp-registry-rhel8@sha256:b6885b85a1220887c6f0640cf2c95a82f190d3f5939a66b582259c57e60d0bbd_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-registry-rhel8@sha256:b6885b85a1220887c6f0640cf2c95a82f190d3f5939a66b582259c57e60d0bbd_amd64 |
| Red Hat | oadp/oadp-velero-plugin-rhel8@sha256:95bc2c1e9419a8c05bff13d05cb21d84ec69c22c15ed3c52484e5e9a17c291e9_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-rhel8@sha256:95bc2c1e9419a8c05bff13d05cb21d84ec69c22c15ed3c52484e5e9a17c291e9_amd64 |
| Red Hat | oadp/oadp-mustgather-rhel8@sha256:d178bbef0c7e2bea002ec1a0b294472f42c7c5c9642d174492baa2770ce6527f_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-mustgather-rhel8@sha256:d178bbef0c7e2bea002ec1a0b294472f42c7c5c9642d174492baa2770ce6527f_amd64 |
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:01f0f6be391bdb11e9cb19c00540ab305a758dae68e45ca0f045afb801748485_amd64 as a component of 8Base-OADP-1.0 | * |
| Red Hat | oadp/oadp-registry-rhel8@sha256:b6885b85a1220887c6f0640cf2c95a82f190d3f5939a66b582259c57e60d0bbd_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-registry-rhel8@sha256:b6885b85a1220887c6f0640cf2c95a82f190d3f5939a66b582259c57e60d0bbd_amd64 |
| Red Hat | oadp/oadp-operator-bundle@sha256:7ac193a2157e5519f5a5e6908d7378a6c231bc4221b350f9ecd908f86866edf8_amd64 as a component of 8Base-OADP-1.0 | * |
| Red Hat | oadp/oadp-velero-plugin-rhel8@sha256:95bc2c1e9419a8c05bff13d05cb21d84ec69c22c15ed3c52484e5e9a17c291e9_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-rhel8@sha256:95bc2c1e9419a8c05bff13d05cb21d84ec69c22c15ed3c52484e5e9a17c291e9_amd64 |
| Red Hat | oadp/oadp-velero-rhel8@sha256:a0f5d406010ba1161572c009e9d3dd62b36124bf57cbc29edff39ac57f1035bb_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-rhel8@sha256:a0f5d406010ba1161572c009e9d3dd62b36124bf57cbc29edff39ac57f1035bb_amd64 |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:b391390d15088e8afd3297e0dbc1ca6ab6e54ff6a61c7e28b2fe7f8f6777c651_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:b391390d15088e8afd3297e0dbc1ca6ab6e54ff6a61c7e28b2fe7f8f6777c651_amd64 |
| Red Hat | oadp/oadp-rhel8-operator@sha256:c93d727f3244175c409e7e23301152519a4ac4a6cdfba8107b99f622f0a394de_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-rhel8-operator@sha256:c93d727f3244175c409e7e23301152519a4ac4a6cdfba8107b99f622f0a394de_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:a2bfb3a1bc7e6788f758af6e7f88b9c07426a4509f9ba329f7adc3a749703995_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:a2bfb3a1bc7e6788f758af6e7f88b9c07426a4509f9ba329f7adc3a749703995_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:34c535174f0c67b85343d2dedc698c4909d212581bccf4004583916d65c079a0_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:34c535174f0c67b85343d2dedc698c4909d212581bccf4004583916d65c079a0_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-microsoft-azure-rhel8@sha256:8b8ff5365ce8bcc94719fd4c84087140456e035ef5390fe327df90d8a527760d_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-microsoft-azure-rhel8@sha256:8b8ff5365ce8bcc94719fd4c84087140456e035ef5390fe327df90d8a527760d_amd64 |
…and 4 more
Timeline
- Jul 27, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 29, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:4289 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2196027 issue
- https://issues.redhat.com/browse/OADP-1504 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4289.json advisory
- https://access.redhat.com/security/cve/CVE-2023-24540 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-24540 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-24540 advisory
- https://go.dev/issue/59721 advisory
- https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU advisory