CVE-2023-24539

Updated: 2025-04-29 17:37:49.834941

Description:

Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU golang 1.19.13 7.3 HIGH Already Fixed 2025-05-07 04:13:37
AlmaLinux 9.2 ESU buildah 1.29.1 7.3 HIGH Already Fixed 2025-05-12 04:14:25
AlmaLinux 9.2 ESU podman 4.4.1 7.3 HIGH Needs Triage 2025-05-16 22:42:39