Closed
Description
In GitHub Security Advisory GHSA-55vm-3vq3-4jpc, there is a vulnerability in the following Go packages or modules:
Unit | Fixed | Vulnerable Ranges |
---|---|---|
github.com/answerdev/answer | 1.0.6 | < 1.0.6 |
Cross references:
- Module github.com/answerdev/answer appears in issue x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-65px-4cpf-697r #1541 EFFECTIVELY_PRIVATE
- Module github.com/answerdev/answer appears in issue x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-4cwh-8w4g-jxxh #1550 NOT_IMPORTABLE
- Module github.com/answerdev/answer appears in issue x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-hjmr-xm25-36mh #1551 NOT_IMPORTABLE
- Module github.com/answerdev/answer appears in issue x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-p7wj-c85f-xq9h #1552 EFFECTIVELY_PRIVATE
- Module github.com/answerdev/answer appears in issue x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-qx34-47fc-vv79 #1553 NOT_IMPORTABLE
- Module github.com/answerdev/answer appears in issue x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-rmw8-7823-wp7f #1554 EFFECTIVELY_PRIVATE
- Module github.com/answerdev/answer appears in issue x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-6cvf-m58q-h9wf #1592 NOT_IMPORTABLE
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/answerdev/answer
versions:
- fixed: 1.0.6
packages:
- package: github.com/answerdev/answer
description: Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer
prior to 1.0.6.
cves:
- CVE-2023-1240
ghsas:
- GHSA-55vm-3vq3-4jpc
references:
- web: https://nvd.nist.gov/vuln/detail/CVE-2023-1240
- fix: https://github.com/answerdev/answer/commit/90bfa0dcc7b49482f1d1e31aee3ab073f3c13dd9
- web: https://huntr.dev/bounties/a24f57a4-22e3-4a17-8227-6a410a11498a
- advisory: https://github.com/advisories/GHSA-55vm-3vq3-4jpc