Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2020-09-02 10:15
Updated : 2021-09-16 06:19
NVD link : CVE-2020-24553
Mitre link : CVE-2020-24553
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
golang
- go
oracle
- communications_cloud_native_core_policy
fedoraproject
- fedora
opensuse
- leap