CVE Published: 11/05/2023 |
CVE Updated: 15/11/2024 |
CVE Year: 2023 Source: Go |
Vendor: Go standard library |
Product: html/template Status : PUBLISHED
CVE-2023-24540 Description
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.