Bugzilla – Bug 1213933
VUL-0: CVE-2023-3978: hugo: embedded golang.org/x/net/html is vulnerable to Cross site scripting
Last modified: 2023-08-03 14:15:30 UTC
CVE-2023-3978 Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3978 https://bugzilla.redhat.com/show_bug.cgi?id=2228689 https://www.cve.org/CVERecord?id=CVE-2023-3978 https://go.dev/cl/514896 https://go.dev/issue/61615 https://pkg.go.dev/vuln/GO-2023-1988
SUSE packages: Those contain the vulnerable go module but there is no call trace to the vulnerable code: SUSE:ALP:Source:Standard:1.0/cni SUSE:SLE-15-SP5:Update/cni SUSE:SLE-15-SP5:Update/yq
openSUSE packages: Affected: - openSUSE:Factory/hugo