Improper handling of empty HTML attributes in html/template
CVE-2023-29400
7.3HIGH
What is CVE-2023-29400?
This vulnerability arises from templates in the Go programming language that allow actions in unquoted HTML attributes. When these templates are executed with empty input values, they can lead to unexpected behaviour due to HTML normalization rules. This flaw may permit the injection of arbitrary attributes into HTML tags, posing a significant security risk that could be harnessed for malicious purposes.
Affected Version(s)
html/template 0 < 1.19.9
html/template 1.20.0-0 < 1.20.4