Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.
{
"binaries": [
{
"binary_name": "golang-1.20",
"binary_version": "1.20.3-1ubuntu0.1~20.04"
},
{
"binary_name": "golang-1.20-doc",
"binary_version": "1.20.3-1ubuntu0.1~20.04"
},
{
"binary_name": "golang-1.20-go",
"binary_version": "1.20.3-1ubuntu0.1~20.04"
},
{
"binary_name": "golang-1.20-go-dbgsym",
"binary_version": "1.20.3-1ubuntu0.1~20.04"
},
{
"binary_name": "golang-1.20-src",
"binary_version": "1.20.3-1ubuntu0.1~20.04"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "golang-1.20",
"binary_version": "1.20.3-1ubuntu0.1~22.04"
},
{
"binary_name": "golang-1.20-doc",
"binary_version": "1.20.3-1ubuntu0.1~22.04"
},
{
"binary_name": "golang-1.20-go",
"binary_version": "1.20.3-1ubuntu0.1~22.04"
},
{
"binary_name": "golang-1.20-go-dbgsym",
"binary_version": "1.20.3-1ubuntu0.1~22.04"
},
{
"binary_name": "golang-1.20-src",
"binary_version": "1.20.3-1ubuntu0.1~22.04"
}
],
"availability": "No subscription required"
}