CVE-2023-24540
Improper handling of JavaScript whitespace in html/template
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t
\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.
A flaw was found in golang, where not all valid JavaScript white-space characters were considered white space. Due to this issue, templates containing white-space characters outside of the character set "\t
\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Issues addressed include a denial of service vulnerability.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-01-25 CVE Reserved
- 2023-05-11 CVE Published
- 2025-01-24 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-176: Improper Handling of Unicode Encoding
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://go.dev/cl/491616 | 2023-11-07 | |
https://go.dev/issue/59721 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://pkg.go.dev/vuln/GO-2023-1752 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2023-24540 | 2024-06-26 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2196027 | 2024-06-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Golang Search vendor "Golang" | Go Search vendor "Golang" for product "Go" | < 1.19.9 Search vendor "Golang" for product "Go" and version " < 1.19.9" | - |
Affected
| ||||||
Golang Search vendor "Golang" | Go Search vendor "Golang" for product "Go" | >= 1.20.0 < 1.20.4 Search vendor "Golang" for product "Go" and version " >= 1.20.0 < 1.20.4" | - |
Affected
|