-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/rancher/norman | go | < 0.0.0-20240207153100-3bb70b772b52 | 0.0.0-20240207153100-3bb70b772b52 |
The vulnerability stems from two key areas: 1) In html.go, user-controlled URLs were inserted into HTML attributes without OWASP-recommended attribute encoding, as evidenced by the addition of encodeAttribute in the patch. 2) In url.go, the previous string-based URL construction method didn't properly escape path components, allowing XSS payloads in URLs. The patches specifically address these by introducing attribute encoding and using url.URL's safe path construction methods.
Ongoing coverage of React2Shell