CVE-2024-55601
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo
描述
Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks. Those whoa re impacted are Hugo users who do not trust their Markdown content files and are using one or more of these templates: `_default/_markup/render-link.html` from `v0.123.0`; `_default/_markup/render-image.html` from `v0.123.0`; `_default/_markup/render-table.html` from `v0.134.0`; and/or `shortcodes/youtube.html` from `v0.125.0`. This issue is patched in v0.139.4. As a workaround, one may replace an affected component with user defined templates or disable the internal templates.
如何修補 CVE-2024-55601
要修補 CVE-2024-55601,請將受影響套件升級到下列已修補版本。
- —未列出修補版本
- —升級至 0.139.4 或更新版本
- —升級至 0.139.4 或更新版本
CVE-2024-55601 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0
- >= 0.123.0, < 0.139.4
- >= 0.123.0, < 0.139.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |