Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://go.dev/issue/59721 | patch issue tracking |
https://go.dev/cl/491616 | patch |
https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU | release notes mailing list |
https://pkg.go.dev/vuln/GO-2023-1752 | vendor advisory |
https://security.netapp.com/advisory/ntap-20241115-0008/ |