Cross-site scripting in Go programming language - CVE-2020-24553

 

Cross-site scripting in Go programming language - CVE-2020-24553

Published: September 2, 2020 / Updated: September 10, 2020


Vulnerability identifier: #VU46580
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2020-24553
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Go programming language
Arch Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
openshift-serverless-clients (Red Hat package)
go (Alpine package)
delve
golang-1.10-go (Ubuntu package)
golang-1.10 (Ubuntu package)
golang-1.14 (Ubuntu package)
golang-1.14-go (Ubuntu package)
golang
golang-bin
golang-tests
golang-src
golang-misc
golang-docs
golang-race
go-toolset
ObjectScale
Dell PowerProtect Cyber Recovery
Oracle Communications Cloud Native Core Policy
QRadar Suite
IBM Cloud Automation Manager
IBM Robotic Process Automation
Netcool Operations Insight
IBM API Connect
Red Hat OpenShift Serverless
Cloud Pak for Data

How to mitigate CVE-2020-24553

Update to version 1.14.8.

Go programming language - update to 1.14.8
openshift-serverless-clients (Red Hat package) - update to 0.18.4-2.el8
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.17.0
go (Alpine package) - update to 1.15.2-r0
IBM API Connect - addressed in versions 10.0.1.4, 10.0.3, 2018.4.1.17
IBM Robotic Process Automation - update to 21.0.3.1
delve - update to 1.5.0-2
Netcool Operations Insight - update to 1.6.6
golang-1.10-go (Ubuntu package) - addressed in versions 1.10.4-2ubuntu1~16.04.2, 1.10.4-2ubuntu1~18.04.2
golang-1.10 (Ubuntu package) - addressed in versions 1.10.4-2ubuntu1~16.04.2, 1.10.4-2ubuntu1~18.04.2
Red Hat OpenShift Serverless - update to 1.12.0
golang-1.14 (Ubuntu package) - addressed in versions 1.14.3-2ubuntu2~20.04.2, 1.14.7-2ubuntu1.1
golang-1.14-go (Ubuntu package) - addressed in versions 1.14.3-2ubuntu2~20.04.2, 1.14.7-2ubuntu1.1
golang - addressed in versions 1.15.1-1.fc33, 1.15.2-1.el6, 1.15.2-1.el7
golang-bin - update to 1.15.14-1
golang-tests - update to 1.15.14-1
golang-src - update to 1.15.14-1
golang-misc - update to 1.15.14-1
golang-docs - update to 1.15.14-1
golang-race - update to 1.15.14-1
golang - update to 1.15.14-1
go-toolset - update to 1.15.14-1
Cloud Pak for Data - update to 3.0.1 lite patch 5
Dell PowerProtect Cyber Recovery - update to 19.14.0.1

External References

Related Security Bulletins