Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-24540


Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.


Published

2023-05-11T16:15:09.687

Last Modified

2025-01-24T17:15:10.893

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application golang go < 1.19.9 Yes
Application golang go < 1.20.4 Yes

References