CVE-2024-24785

Source
https://cve.org/CVERecord?id=CVE-2024-24785
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-24785.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-24785
Aliases
Downstream
AZL (4)
BELL (1)
CGA (724)
CLSA (1)
DEBIAN (1)
MINI (3)
OESA (8)
openSUSE (2)
RHSA (7)
RLSA (2)
SUSE (8)
UBUNTU (1)
Related
Withdrawn
2026-01-27T04:20:09Z
Published
2024-03-05T23:15:07Z
Modified
2026-07-17T21:02:24Z
Summary
[none]
Details

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

References

Affected packages