Cross-site scripting in Go programming language - CVE-2023-39319

 

Cross-site scripting in Go programming language - CVE-2023-39319

Published: September 8, 2023


Vulnerability identifier: #VU80573
CSH Severity: Medium
CVSS v4 BT: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-39319
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists within the html/template package caused by improperly applied rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. A remote attacker can pass specially crafted input to the application and execute arbitrary HTML and script code in user's browser in context of vulnerable website.


Affected software

Go programming language
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
Fedora
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
AdGuard Home
IBM Qradar SIEM
Run Once Duration Override Operator for Red Hat OpenShift
Service Interconnect
Consul
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift distributed tracing (RHOSDT)
Operations Dashboard
IBM MQ Operator
IBM Cloud Pak for Data Scheduling
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Robotic Process Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Multicluster Engine for Kubernetes
Juniper Secure Analytics (JSA)
Splunk Enterprise
IBM Business Automation Manager Open Editions
ObjectScale
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Storage Protect Server
IBM Sterling Order Management
Storage Protect Plus Container Agent
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
golang-1.18-src (Ubuntu package)
golang-1.18-go (Ubuntu package)
golang-1.18 (Ubuntu package)
crun-wasm (Red Hat package)
toolbox (Red Hat package)
toolbox-tests
toolbox
udica
wasmedge (Red Hat package)
golang-github-prometheus-promu (Red Hat package)
coreos-installer (Red Hat package)
butane (Red Hat package)
containernetworking-plugins (Red Hat package)
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
google-benchmark (Red Hat package)
crun (Red Hat package)
aardvark-dns
netavark
skopeo (Red Hat package)
spdlog (Red Hat package)
gtest (Red Hat package)
fuse-overlayfs
crun
skopeo-tests
skopeo
golang
golang-devel
golang-help
golang-1.17-src (Ubuntu package)
golang-1.17 (Ubuntu package)
golang-1.17-go (Ubuntu package)
golang-1.20-src (Ubuntu package)
golang-1.20-go (Ubuntu package)
golang-1.20 (Ubuntu package)
go1.20-openssl-debuginfo
go1.20-openssl-race
go1.20-openssl
go1.20-openssl-doc
go1.20
go1.20-debuginfo
go1.20-race
go1.20-doc
golang-src
golang-bin
golang-shared
golang-docs
golang-misc
golang-tests
dev-lang/go
golang-1.21-src (Ubuntu package)
golang-1.21 (Ubuntu package)
golang-1.21-go (Ubuntu package)
go1.21-doc
go1.21
go1.21-race
go1.21-openssl-doc
go1.21-openssl-race
go1.21-openssl
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
buildah
buildah-tests
containers-common (Red Hat package)
containers-common
conmon (Red Hat package)
conmon
nmstate (Red Hat package)
haproxy (Red Hat package)
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
kata-containers (Red Hat package)
catch (Red Hat package)
criu
python3-criu
criu-libs
crit
criu-devel
libslirp-devel
libslirp
podman (Red Hat package)
python3-podman
podman-catatonit
podman
podman-gvproxy
podman-plugins
podman-docker
podman-remote
podman-tests
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
rust-afterburn (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
fmt (Red Hat package)
ovn23.09 (Red Hat package)
cockpit-podman
IBM Cloud Pak System
IBM Security Verify Access
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2023-39319

Install updates from vendor's website.

Go programming language - addressed in versions 1.20.8, 1.21.1
AdGuard Home - addressed in versions 0.107.37, 0.108.0-b.45
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Service Interconnect - update to 1.5.3
Migration Toolkit for Containers - update to 1.7.14
Consul - addressed in versions 1.14.10, 1.15.6, 1.16.2
Multicluster Engine for Kubernetes - addressed in versions 2.1.9, 2.2.9, 2.3.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.8, 2.7.9, 2.8.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.22, 4.13.24, 4.14.0, 4.14.2, 4.14.4
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
IBM Business Automation Manager Open Editions - update to 9.0.1
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Operations Dashboard - update to 2022.2.1-16
golang-1.18-src (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18-go (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
golang-1.18 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.18.1-1ubuntu1.2, 1.18.1-1ubuntu1~20.04.3
crun-wasm (Red Hat package) - addressed in versions 0.0-3.rhaos4.14.el8, 1.8.5-3.rhaos4.14.el9
toolbox (Red Hat package) - addressed in versions 0.0.99.5-2.el9, 0.1.2-1.rhaos4.14.el9
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
wasmedge (Red Hat package) - update to 0.12.1-2.rhaos4.14.el9
golang-github-prometheus-promu (Red Hat package) - update to 0.15.0-15.1.gitd5383c5.el8
coreos-installer (Red Hat package) - addressed in versions 0.17.0-1.rhaos4.14.el8, 0.17.0-1.rhaos4.14.el9
butane (Red Hat package) - update to 0.19.0-1.1.rhaos4.14.el8
containernetworking-plugins (Red Hat package) - update to 1.0.1-11.1.rhaos4.14.el8
runc (Red Hat package) - addressed in versions 1.1.9-2.1.rhaos4.14.el8, 1.1.9-2.1.rhaos4.14.el9
runc - update to 1.1.12-1.0.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.2.0
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
ObjectScale - update to 1.4.0
containernetworking-plugins - update to 1.4.0-2.0.1
google-benchmark (Red Hat package) - update to 1.8.2-1.el9
crun (Red Hat package) - addressed in versions 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
skopeo (Red Hat package) - addressed in versions 1.11.2-10.1.rhaos4.14.el8, 1.11.2-10.1.rhaos4.14.el9, 1.13.3-3.el9_3
spdlog (Red Hat package) - update to 1.12.0-1.rhaos4.14.el9
gtest (Red Hat package) - update to 1.13.0-1.el9
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
golang - update to 1.15.7-36
golang-devel - update to 1.15.7-36
golang-help - update to 1.15.7-36
golang-1.17-src (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang-1.17 (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang-1.17-go (Ubuntu package) - update to 1.17.13-3ubuntu1.2
golang - addressed in versions 1.19.13-1.el7, 1.19.13-1.fc37, 1.20.8-1.fc38, 1.21.1-1.fc39
golang-1.20-src (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20-go (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang-1.20 (Ubuntu package) - addressed in versions 1.20.3-1ubuntu0.1~20.04.1, 1.20.3-1ubuntu0.1~22.04.1, 1.20.3-1ubuntu0.2, 1.20.8-1ubuntu0.23.10.1
golang - update to 1.20.8-1.47
go1.20-openssl-debuginfo - update to 1.20.8.1-150000.1.11.1
go1.20-openssl-race - update to 1.20.8.1-150000.1.11.1
go1.20-openssl - update to 1.20.8.1-150000.1.11.1
go1.20-openssl-doc - update to 1.20.8.1-150000.1.11.1
go1.20 - update to 1.20.8-150000.1.23.1
go1.20-debuginfo - update to 1.20.8-150000.1.23.1
go1.20-race - update to 1.20.8-150000.1.23.1
go1.20-doc - update to 1.20.8-150000.1.23.1
golang-src - update to 1.20.9-1
golang - update to 1.20.9-1
golang-bin - update to 1.20.9-1
golang-shared - update to 1.20.9-1
golang-docs - update to 1.20.9-1
golang-misc - update to 1.20.9-1
golang-tests - update to 1.20.9-1
dev-lang/go - update to 1.20.10
golang-1.21-src (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21 (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
golang-1.21-go (Ubuntu package) - addressed in versions 1.21.1-1ubuntu0.23.10.1, 1.21.1-1~ubuntu20.04.2, 1.21.1-1~ubuntu22.04.2, 1.21.1-1~ubuntu23.04.2
go1.21-doc - update to 1.21.1-150000.1.6.1
go1.21 - update to 1.21.1-150000.1.6.1
go1.21-race - update to 1.21.1-150000.1.6.1
go1.21-openssl-doc - update to 1.21.4.1-150000.1.5.1
go1.21-openssl-race - update to 1.21.4.1-150000.1.5.1
go1.21-openssl - update to 1.21.4.1-150000.1.5.1
cri-tools (Red Hat package) - addressed in versions 1.27.0-2.1.el8, 1.27.0-2.1.el9
cri-o (Red Hat package) - addressed in versions 1.27.1-8.1.rhaos4.14.git3fecb83.el8, 1.27.1-8.1.rhaos4.14.git3fecb83.el9, 1.27.1-13.1.rhaos4.14.git956c5f7.el8, 1.27.1-13.1.rhaos4.14.git956c5f7.el9
buildah (Red Hat package) - addressed in versions 1.29.1-10.1.rhaos4.14.el8, 1.29.1-10.1.rhaos4.14.el9, 1.31.3-2.el9_3
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common (Red Hat package) - update to 1-51.rhaos4.14.el8
containers-common - update to 1-81.0.1
IBM MQ Operator - addressed in versions 2.0.17, 3.0.0
conmon (Red Hat package) - addressed in versions 2.1.7-3.1.rhaos4.14.el8, 2.1.7-3.1.rhaos4.14.el9
conmon - update to 2.1.10-1
nmstate (Red Hat package) - update to 2.2.12-1.rhaos4.14.el8
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
haproxy (Red Hat package) - update to 2.6.13-1.rhaos4.14.el8
ignition (Red Hat package) - update to 2.16.2-1.1.rhaos4.14.el9
container-selinux (Red Hat package) - addressed in versions 2.221.0-1.rhaos4.14.el8, 2.221.0-2.rhaos4.14.el9, 2.223.0-1.rhaos4.14.el8, 2.223.0-2.rhaos4.14.el9
container-selinux - update to 2.229.0-2
kata-containers (Red Hat package) - update to 3.1.3-4.rhaos4.14.el9
catch (Red Hat package) - update to 3.3.2-1.el9
criu - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
IBM Cloud Pak for Watson AIOps - update to 4.4.0
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-10.1.rhaos4.14.el8, 4.4.1-10.1.rhaos4.14.el9, 4.6.1-7.el9_3
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
python3-podman - update to 4.9.0-1
podman-catatonit - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
openshift-kuryr (Red Hat package) - update to 4.14.0-202309272140.p0.g8926a29.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - update to 4.14.0-202309272140.p0.gd2acdd5.assembly.stream.el8
openshift-ansible (Red Hat package) - addressed in versions 4.14.0-202310062327.p0.gf781421.assembly.stream.el8, 4.14.0-202310062327.p0.gf781421.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.14.0-202310191146.p0.g0c63f9d.assembly.stream.el8, 4.14.0-202310191146.p0.g0c63f9d.assembly.stream.el9, 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el8, 4.14.0-202311031050.p0.g9b1e0d2.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.14.0-202310210404.p0.gf67aeb3.assembly.stream.el8, 4.14.0-202310210404.p0.gf67aeb3.assembly.stream.el9
rust-afterburn (Red Hat package) - update to 5.4.3-1.rhaos4.14.el9
kernel (Red Hat package) - addressed in versions 5.14.0-284.36.1.el9_2, 5.14.0-284.40.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.36.1.rt14.321.el9_2, 5.14.0-284.40.1.rt14.325.el9_2
Storage Protect Server - update to 8.1.23
fmt (Red Hat package) - update to 9.1.0-1.el9
IBM Security Verify Access - update to 10.0.9
IBM Sterling Order Management - update to 10.0.2403.1
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
IBM CICS TX Standard - update to 11.1.0.0 ifix15
IBM CICS TX Advanced - update to 11.1.0.0 ifix15
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
ovn23.09 (Red Hat package) - update to 23.09.0-37.el9fdp
cockpit-podman - update to 84.1-1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-14, 2023.2.1-3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14

External References

Related Security Bulletins