Skip to content

x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-55vm-3vq3-4jpc #1613

Closed
@GoVulnBot

Description

@GoVulnBot

In GitHub Security Advisory GHSA-55vm-3vq3-4jpc, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/answerdev/answer 1.0.6 < 1.0.6

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: github.com/answerdev/answer
    versions:
      - fixed: 1.0.6
    packages:
      - package: github.com/answerdev/answer
description: Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer
    prior to 1.0.6.
cves:
  - CVE-2023-1240
ghsas:
  - GHSA-55vm-3vq3-4jpc
references:
  - web: https://nvd.nist.gov/vuln/detail/CVE-2023-1240
  - fix: https://github.com/answerdev/answer/commit/90bfa0dcc7b49482f1d1e31aee3ab073f3c13dd9
  - web: https://huntr.dev/bounties/a24f57a4-22e3-4a17-8227-6a410a11498a
  - advisory: https://github.com/advisories/GHSA-55vm-3vq3-4jpc

Metadata

Metadata

Assignees

No one assigned

    Labels

    excluded: NOT_IMPORTABLEThis vulnerability only exists in a binary and is not importable.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions