Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2020-09-02 17:15
Updated : 2024-11-21 05:14
NVD link : CVE-2020-24553
Mitre link : CVE-2020-24553
CVE.ORG link : CVE-2020-24553
JSON object : View
Products Affected
golang
- go
oracle
- communications_cloud_native_core_policy
fedoraproject
- fedora
opensuse
- leap
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')