Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2020-29509

Published: August 31, 2023Last modified: August 31, 2023

Description

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

Severity score breakdown

ParameterValue
Base score5.6
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita LinuxStreamgoNot affected (1.21.0-r2)

References

ON THIS PAGE