CVE-2024-24785

Source
https://cve.org/CVERecord?id=CVE-2024-24785
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-24785.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-24785
Aliases
Downstream
Related
Published
2024-03-05T23:15:07Z
Modified
2026-01-14T08:56:05.977099Z
Summary
[none]
Details

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

References

Affected packages