OESA-2023-1294

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1294
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1294.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1294
Upstream
Published
2023-05-26T11:05:17Z
Modified
2025-08-12T05:18:39.900575Z
Summary
golang security update
Details

The Go Programming Language.

Security Fix(es):

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.(CVE-2023-29400)

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.(CVE-2023-24539)

Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.(CVE-2023-24540)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / golang

Package

Name
golang
Purl
pkg:rpm/openEuler/golang&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.15.7-27.oe1

Ecosystem specific

{
    "x86_64": [
        "golang-1.15.7-27.oe1.x86_64.rpm"
    ],
    "src": [
        "golang-1.15.7-27.oe1.src.rpm"
    ],
    "aarch64": [
        "golang-1.15.7-27.oe1.aarch64.rpm"
    ],
    "noarch": [
        "golang-devel-1.15.7-27.oe1.noarch.rpm",
        "golang-help-1.15.7-27.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / golang

Package

Name
golang
Purl
pkg:rpm/openEuler/golang&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.15.7-27.oe1

Ecosystem specific

{
    "x86_64": [
        "golang-1.15.7-27.oe1.x86_64.rpm"
    ],
    "src": [
        "golang-1.15.7-27.oe1.src.rpm"
    ],
    "aarch64": [
        "golang-1.15.7-27.oe1.aarch64.rpm"
    ],
    "noarch": [
        "golang-help-1.15.7-27.oe1.noarch.rpm",
        "golang-devel-1.15.7-27.oe1.noarch.rpm"
    ]
}

openEuler:22.03-LTS / golang

Package

Name
golang
Purl
pkg:rpm/openEuler/golang&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.17.3-18.oe2203sp1

Ecosystem specific

{
    "x86_64": [
        "golang-1.17.3-18.oe2203.x86_64.rpm",
        "golang-1.17.3-18.oe2203sp1.x86_64.rpm"
    ],
    "src": [
        "golang-1.17.3-18.oe2203.src.rpm",
        "golang-1.17.3-18.oe2203sp1.src.rpm"
    ],
    "aarch64": [
        "golang-1.17.3-18.oe2203.aarch64.rpm",
        "golang-1.17.3-18.oe2203sp1.aarch64.rpm"
    ],
    "noarch": [
        "golang-help-1.17.3-18.oe2203.noarch.rpm",
        "golang-devel-1.17.3-18.oe2203.noarch.rpm",
        "golang-devel-1.17.3-18.oe2203sp1.noarch.rpm",
        "golang-help-1.17.3-18.oe2203sp1.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / golang

Package

Name
golang
Purl
pkg:rpm/openEuler/golang&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.17.3-18.oe2203sp1

Ecosystem specific

{
    "x86_64": [
        "golang-1.17.3-18.oe2203sp1.x86_64.rpm"
    ],
    "src": [
        "golang-1.17.3-18.oe2203sp1.src.rpm"
    ],
    "aarch64": [
        "golang-1.17.3-18.oe2203sp1.aarch64.rpm"
    ],
    "noarch": [
        "golang-devel-1.17.3-18.oe2203sp1.noarch.rpm",
        "golang-help-1.17.3-18.oe2203sp1.noarch.rpm"
    ]
}