Cross-site scripting in html - CVE-2023-3978
Published: August 9, 2023
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Server Module
SUSE Manager Proxy
SUSE Manager Proxy Module
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Anolis OS
Fedora
SUSE Manager Client Tools for RHEL, Liberty and Clones
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
openSUSE Leap
Ubuntu
IBM Observability with Instana
Consul Enterprise
Cryostat
Migration Toolkit for Virtualization
Netcool Operations Insight
IBM MQ Operator
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Cloud Pak for Business Automation
Juniper Cloud Native Router
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Storage Fusion Data Foundation
IBM Planning Analytics Workspace
Dell PowerProtect Cyber Recovery
Splunk Enterprise
QRadar Suite
golang-golang-x-net-dev (Ubuntu package)
golang-golang-x-net (Ubuntu package)
crun-wasm (Red Hat package)
toolbox
toolbox-tests
toolbox (Red Hat package)
mgrctl-debuginfo
mgrctl-bash-completion
mgrctl-zsh-completion
mgrctl
mgrctl-lang
scap-security-guide-redhat
udica
wire-debuginfo
wire
adsys (Ubuntu package)
wasmedge (Red Hat package)
golang-x-net
golang-github-prometheus-promu (Red Hat package)
golang-github-prometheus-promu
coreos-installer (Red Hat package)
butane (Red Hat package)
containernetworking-plugins (Red Hat package)
golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter-debuginfo
nerdctl
runc (Red Hat package)
runc
slirp4netns
xq
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
google-benchmark (Red Hat package)
crun
crun (Red Hat package)
skopeo (Red Hat package)
spdlog (Red Hat package)
fuse-overlayfs
gtest (Red Hat package)
skopeo-tests
skopeo
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
buildah-tests
buildah
containers-common (Red Hat package)
rclone
containers-common
ecs-init
conmon (Red Hat package)
conmon
nmstate (Red Hat package)
haproxy (Red Hat package)
caddy
golang-github-onsi-ginkgo-2
ignition (Red Hat package)
gh
container-selinux
container-selinux (Red Hat package)
kata-containers (Red Hat package)
amazon-ssm-agent
catch (Red Hat package)
criu-libs
criu-devel
criu
python3-criu
crit
mgr-daemon
python2-spacewalk-client-setup
python2-spacewalk-client-tools
spacewalk-check
spacewalk-client-setup
python2-spacewalk-check
spacewalk-client-tools
python3-spacewalk-client-setup
python3-spacewalk-check
python3-spacewalk-client-tools
libslirp
libslirp-devel
podman (Red Hat package)
python3-podman
podman-tests
podman-docker
podman-catatonit
podman-remote
podman-plugins
podman-gvproxy
podman
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
python2-uyuni-common-libs
python3-uyuni-common-libs
spacecmd
rust-afterburn (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
fmt (Red Hat package)
ovn23.09 (Red Hat package)
cockpit-podman
Cloud Pak for Data
IBM CICS TX Standard
IBM CICS TX Advanced
Junos cRPD
How to mitigate CVE-2023-3978
Migration Toolkit for Containers - update to 1.7.13
Consul Enterprise - addressed in versions 1.14.9, 1.15.5, 1.16.1
OpenShift Service Mesh - update to 2.4.5
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.48, 4.13.17, 4.14.0, 4.14.2, 4.14.14, 4.14.22, 4.14.42, 4.15.0
Storage Fusion Data Foundation - update to 4.18.2
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
golang-golang-x-net-dev (Ubuntu package) - addressed in versions 1:0.0+git20160110.4fd4a9f-1ubuntu0.1~esm2, 1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm2, 1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm2
golang-golang-x-net (Ubuntu package) - addressed in versions 1:0.0+git20211209.491a49a+dfsg-1ubuntu0.1~esm2, 1:0.21.0+dfsg-1ubuntu0.1~esm2
crun-wasm (Red Hat package) - addressed in versions 0.0-3.rhaos4.14.el8, 1.8.5-3.rhaos4.14.el9
toolbox - update to 0.0.99.4-5.0.1
toolbox-tests - update to 0.0.99.4-5.0.1
toolbox (Red Hat package) - update to 0.1.2-1.rhaos4.14.el9
mgrctl-debuginfo - addressed in versions 0.1.23-1.11.1, 0.1.23-1.13.2, 0.1.23-150000.1.13.3
mgrctl-bash-completion - addressed in versions 0.1.23-1.11.1, 0.1.23-1.13.2, 0.1.23-150000.1.13.3
mgrctl-zsh-completion - addressed in versions 0.1.23-1.11.1, 0.1.23-1.13.2, 0.1.23-150000.1.13.3
mgrctl - addressed in versions 0.1.23-1.11.1, 0.1.23-1.13.2, 0.1.23-150000.1.13.3
mgrctl-lang - update to 0.1.23-150000.1.13.3
scap-security-guide-redhat - update to 0.1.74-1.29.1
udica - update to 0.2.6-20
wire-debuginfo - update to 0.6.0-150000.1.17.4
wire - update to 0.6.0-150000.1.17.4
adsys (Ubuntu package) - addressed in versions 0.9.2~20.04.2ubuntu0.1+esm1, 2.0.11-0ubuntu1~16.04.4+esm2, 2.3.7-0ubuntu0.16.04.1+esm2, 3.0.3-0ubuntu1~18.04.2+esm2
wasmedge (Red Hat package) - update to 0.12.1-2.rhaos4.14.el9
golang-x-net - addressed in versions 0.14.0-1.fc39, 0.20.0-1.el9
golang-github-prometheus-promu (Red Hat package) - update to 0.15.0-15.1.gitd5383c5.el8
golang-github-prometheus-promu - addressed in versions 0.16.0-1.21.3, 0.16.0-150000.3.21.4
coreos-installer (Red Hat package) - addressed in versions 0.17.0-1.rhaos4.14.el8, 0.17.0-1.rhaos4.14.el9
butane (Red Hat package) - update to 0.19.0-1.1.rhaos4.14.el8
containernetworking-plugins (Red Hat package) - update to 1.0.1-11.1.rhaos4.14.el8
golang-github-lusitaniae-apache_exporter - addressed in versions 1.0.8-1.14.1, 1.0.8-1.24.3, 1.0.8-150000.1.23.3
golang-github-lusitaniae-apache_exporter-debuginfo - update to 1.0.8-150000.1.23.3
nerdctl - update to 1.1.0-1
runc (Red Hat package) - addressed in versions 1.1.9-2.1.rhaos4.14.el8, 1.1.9-2.1.rhaos4.14.el9
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.1-1
xq - update to 1.2.4-2.fc40
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
Netcool Operations Insight - update to 1.6.12
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
google-benchmark (Red Hat package) - update to 1.8.2-1.el9
crun - update to 1.8.7-1
crun (Red Hat package) - addressed in versions 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9
QRadar Suite - update to 1.10.22.0
skopeo (Red Hat package) - addressed in versions 1.11.2-10.1.rhaos4.14.el8, 1.11.2-10.1.rhaos4.14.el9
spdlog (Red Hat package) - update to 1.12.0-1.rhaos4.14.el9
fuse-overlayfs - update to 1.12-1.0.1
gtest (Red Hat package) - update to 1.13.0-1.el9
skopeo-tests - update to 1.13.3-3.0.1
skopeo - update to 1.13.3-3.0.1
cri-tools (Red Hat package) - addressed in versions 1.27.0-2.1.el8, 1.27.0-2.1.el9
cri-o (Red Hat package) - addressed in versions 1.27.1-8.1.rhaos4.14.git3fecb83.el8, 1.27.1-8.1.rhaos4.14.git3fecb83.el9
buildah (Red Hat package) - addressed in versions 1.29.1-10.1.rhaos4.14.el8, 1.29.1-10.1.rhaos4.14.el9
buildah-tests - update to 1.31.3-1
buildah - update to 1.31.3-1
containers-common (Red Hat package) - update to 1-51.rhaos4.14.el8
rclone - addressed in versions 1.64.0-1.fc40, 1.70.3-1.el9
containers-common - update to 1-71.0.1
ecs-init - update to 1.79.1-1
IBM MQ Operator - addressed in versions 2.0.17, 3.0.0
IBM Planning Analytics Workspace - update to 2.0.93
conmon (Red Hat package) - addressed in versions 2.1.7-3.1.rhaos4.14.el8, 2.1.7-3.1.rhaos4.14.el9
conmon - update to 2.1.8-1
nmstate (Red Hat package) - update to 2.2.12-1.rhaos4.14.el8
haproxy (Red Hat package) - update to 2.6.13-1.rhaos4.14.el8
caddy - addressed in versions 2.7.4-1.fc39, 2.7.4-1.fc40
golang-github-onsi-ginkgo-2 - update to 2.12.1-1.fc40
ignition (Red Hat package) - update to 2.16.2-1.1.rhaos4.14.el9
gh - update to 2.33.0-1.fc40
container-selinux - update to 2.221.0-1
container-selinux (Red Hat package) - addressed in versions 2.221.0-1.rhaos4.14.el8, 2.221.0-2.rhaos4.14.el9
kata-containers (Red Hat package) - update to 3.1.3-4.rhaos4.14.el9
amazon-ssm-agent - update to 3.2.1630.0-1
catch (Red Hat package) - update to 3.3.2-1.el9
criu-libs - update to 3.18-5
criu-devel - update to 3.18-5
criu - update to 3.18-5
python3-criu - update to 3.18-5
crit - update to 3.18-5
mgr-daemon - addressed in versions 4.3.11-1.53.2, 4.3.11-150000.1.53.5
python2-spacewalk-client-setup - update to 4.3.21-52.104.2
python2-spacewalk-client-tools - update to 4.3.21-52.104.2
spacewalk-check - addressed in versions 4.3.21-52.104.2, 4.3.21-150000.3.97.4
spacewalk-client-setup - addressed in versions 4.3.21-52.104.2, 4.3.21-150000.3.97.4
python2-spacewalk-check - update to 4.3.21-52.104.2
spacewalk-client-tools - addressed in versions 4.3.21-52.104.2, 4.3.21-150000.3.97.4
python3-spacewalk-client-setup - update to 4.3.21-150000.3.97.4
python3-spacewalk-check - update to 4.3.21-150000.3.97.4
python3-spacewalk-client-tools - update to 4.3.21-150000.3.97.4
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
podman (Red Hat package) - addressed in versions 4.4.1-10.1.rhaos4.14.el8, 4.4.1-10.1.rhaos4.14.el9, 4.4.1-11.2.rhaos4.14.el8, 4.4.1-11.2.rhaos4.14.el9, 4.6.1-5.el9
python3-podman - update to 4.6.0-1
podman-tests - update to 4.6.1-8.0.1
podman-docker - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
Cloud Pak for Data - update to 4.8.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
openshift-kuryr (Red Hat package) - update to 4.14.0-202309272140.p0.g8926a29.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - update to 4.14.0-202309272140.p0.gd2acdd5.assembly.stream.el8
openshift-ansible (Red Hat package) - addressed in versions 4.14.0-202310062327.p0.gf781421.assembly.stream.el8, 4.14.0-202310062327.p0.gf781421.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.14.0-202310191146.p0.g0c63f9d.assembly.stream.el8, 4.14.0-202310191146.p0.g0c63f9d.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.14.0-202310210404.p0.gf67aeb3.assembly.stream.el8, 4.14.0-202310210404.p0.gf67aeb3.assembly.stream.el9
python2-uyuni-common-libs - update to 5.0.5-1.45.2
python3-uyuni-common-libs - update to 5.0.5-150000.1.45.3
spacecmd - addressed in versions 5.0.10-1.41.1, 5.0.10-38.150.2, 5.0.10-150000.3.127.3
App Connect Enterprise Certified Container - addressed in versions 5.0.14, 11.2.0
rust-afterburn (Red Hat package) - update to 5.4.3-1.rhaos4.14.el9
kernel (Red Hat package) - addressed in versions 5.14.0-284.36.1.el9_2, 5.14.0-284.54.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.36.1.rt14.321.el9_2, 5.14.0-284.54.1.rt14.339.el9_2
fmt (Red Hat package) - update to 9.1.0-1.el9
IBM CICS TX Standard - update to 11.1.0.0 ifix15
IBM CICS TX Advanced - update to 11.1.0.0 ifix15
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
ovn23.09 (Red Hat package) - update to 23.09.0-37.el9fdp
cockpit-podman - update to 75-1
External References
Related Security Bulletins
- XSS in html package for Go
- Multiple vulnerabilities in Consul Enterprise
- Fedora 39 update for golang-x-net
- Fedora 40 update for caddy
- Fedora 39 update for caddy
- Fedora 40 update for gh
- Fedora 40 update for golang-github-onsi-ginkgo-2
- Fedora 40 update for rclone
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in Cryostat 2 on RHEL 8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Red Hat Enterprise Linux 9 update for podman
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.4
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.14
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in IBM CICS TX Standard and Advanced
- Multiple vulnerabilities in IBM MQ Operator
- Fedora EPEL 9 update for golang-x-net
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Fedora 40 update for xq
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- OpenShift Container Platform release 4.14 update for golang
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM QRadar Suite Software
- Amazon Linux AMI update for ecs-init
- Multiple vulnerabilities in IBM Cloud Pak for Data
- Splunk Enterprise update for third-party components
- SUSE update for SUSE Manager Client Tools
- SUSE update for SUSE Manager Client Tools
- SUSE update for SUSE Manager Client Tools
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Amazon Linux AMI update for nerdctl
- Amazon Linux AMI update for amazon-ssm-agent
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in IBM Storage Fusion Data Foundation
- Fedora EPEL 9 update for rclone
- Ubuntu update for golang-golang-x-net
- Ubuntu update for golang-golang-x-net-dev
- Ubuntu update for adsys