Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.
{
"binaries": [
{
"binary_version": "1.20.3-1ubuntu0.1~20.04",
"binary_name": "golang-1.20"
},
{
"binary_version": "1.20.3-1ubuntu0.1~20.04",
"binary_name": "golang-1.20-doc"
},
{
"binary_version": "1.20.3-1ubuntu0.1~20.04",
"binary_name": "golang-1.20-go"
},
{
"binary_version": "1.20.3-1ubuntu0.1~20.04",
"binary_name": "golang-1.20-go-dbgsym"
},
{
"binary_version": "1.20.3-1ubuntu0.1~20.04",
"binary_name": "golang-1.20-src"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "1.20.3-1ubuntu0.1~22.04",
"binary_name": "golang-1.20"
},
{
"binary_version": "1.20.3-1ubuntu0.1~22.04",
"binary_name": "golang-1.20-doc"
},
{
"binary_version": "1.20.3-1ubuntu0.1~22.04",
"binary_name": "golang-1.20-go"
},
{
"binary_version": "1.20.3-1ubuntu0.1~22.04",
"binary_name": "golang-1.20-go-dbgsym"
},
{
"binary_version": "1.20.3-1ubuntu0.1~22.04",
"binary_name": "golang-1.20-src"
}
],
"availability": "No subscription required"
}