Golang Templates Attributes Injection Vulnerability

description-logoDescription

Templates containing actions in unquoted HTML attributes (e.g. 'attr={{.}}') executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

affected-products-logoAffected Applications

Go Programming Language

CVE References

CVE-2023-29400