Cross-site scripting in Go programming language - CVE-2020-24553
Published: September 2, 2020 / Updated: September 10, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Arch Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
openshift-serverless-clients (Red Hat package)
go (Alpine package)
delve
golang-1.10-go (Ubuntu package)
golang-1.10 (Ubuntu package)
golang-1.14 (Ubuntu package)
golang-1.14-go (Ubuntu package)
golang
golang-bin
golang-tests
golang-src
golang-misc
golang-docs
golang-race
go-toolset
ObjectScale
Dell PowerProtect Cyber Recovery
Oracle Communications Cloud Native Core Policy
QRadar Suite
IBM Cloud Automation Manager
IBM Robotic Process Automation
Netcool Operations Insight
IBM API Connect
Red Hat OpenShift Serverless
Cloud Pak for Data
How to mitigate CVE-2020-24553
openshift-serverless-clients (Red Hat package) - update to 0.18.4-2.el8
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
go (Alpine package) - update to 1.15.2-r0
IBM API Connect - addressed in versions 10.0.1.4, 10.0.3, 2018.4.1.17
IBM Robotic Process Automation - update to 21.0.3.1
delve - update to 1.5.0-2
Netcool Operations Insight - update to 1.6.6
golang-1.10-go (Ubuntu package) - addressed in versions 1.10.4-2ubuntu1~16.04.2, 1.10.4-2ubuntu1~18.04.2
golang-1.10 (Ubuntu package) - addressed in versions 1.10.4-2ubuntu1~16.04.2, 1.10.4-2ubuntu1~18.04.2
Red Hat OpenShift Serverless - update to 1.12.0
golang-1.14 (Ubuntu package) - addressed in versions 1.14.3-2ubuntu2~20.04.2, 1.14.7-2ubuntu1.1
golang-1.14-go (Ubuntu package) - addressed in versions 1.14.3-2ubuntu2~20.04.2, 1.14.7-2ubuntu1.1
golang - addressed in versions 1.15.1-1.fc33, 1.15.2-1.el6, 1.15.2-1.el7
golang-bin - update to 1.15.14-1
golang-tests - update to 1.15.14-1
golang-src - update to 1.15.14-1
golang-misc - update to 1.15.14-1
golang-docs - update to 1.15.14-1
golang-race - update to 1.15.14-1
golang - update to 1.15.14-1
go-toolset - update to 1.15.14-1
Cloud Pak for Data - update to 3.0.1 lite patch 5
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
External References
Related Security Bulletins
- Cross-site scripting in Go programming language
- Cross-site scripting in go (Alpine package)
- Arch Linux update for go
- OpenSUSE Linux update for go1.14
- OpenSUSE Linux update for go1.14
- Amazon Linux AMI update for golang
- Red Hat Enterprise Linux 8 update for the go-toolset:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Red Hat OpenShift Serverless Client security update
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Ubuntu update for golang-1.10
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- XSS in IBM API Connect
- Multiple vulnerabilities in Netcool Operations Insight
- Cross-site scripting in IBM Cloud Automation Manager
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Cross-site scripting in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Suite software
- Anolis OS update for go-toolset:an8 module
- Fedora 33 update for golang
- Fedora EPEL 6 update for golang
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in Dell ObjectScale