Vulnerability Report: GO-2024-3314
- CVE-2024-55601, GHSA-c2xf-9v2r-r2rx
- Affects: github.com/gohugoio/hugo
- Published: Dec 10, 2024
- Modified: Dec 13, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo
For detailed information about this vulnerability, visit https://github.com/gohugoio/hugo/security/advisories/GHSA-c2xf-9v2r-r2rx.
Affected Modules
-
PathGo Versions
-
from v0.123.0 before v0.139.4
Aliases
References
- https://github.com/gohugoio/hugo/security/advisories/GHSA-c2xf-9v2r-r2rx
- https://github.com/gohugoio/hugo/commit/54398f8d572c689f9785d59e907fd910a23401b0
- https://github.com/gohugoio/hugo/releases/tag/v0.139.4
- https://gohugo.io/getting-started/configuration-markup/#renderhooksimageenabledefault
- https://vuln.go.dev/ID/GO-2024-3314.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.