Skip to content

x/vulndb: potential Go vuln in github.com/answerdev/answer: GHSA-9v4v-9fj5-p982 #1616

Closed
@GoVulnBot

Description

@GoVulnBot

In GitHub Security Advisory GHSA-9v4v-9fj5-p982, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/answerdev/answer 1.0.6 < 1.0.6

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: github.com/answerdev/answer
    versions:
      - fixed: 1.0.6
    packages:
      - package: github.com/answerdev/answer
description: Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer
    prior to 1.0.6.
cves:
  - CVE-2023-1237
ghsas:
  - GHSA-9v4v-9fj5-p982
references:
  - web: https://nvd.nist.gov/vuln/detail/CVE-2023-1237
  - fix: https://github.com/answerdev/answer/commit/0566894a2c0e13cf07d877f41467e2e21529fee8
  - web: https://huntr.dev/bounties/cc2aa618-05da-495d-a5cd-51c40557d481
  - advisory: https://github.com/advisories/GHSA-9v4v-9fj5-p982

Metadata

Metadata

Assignees

No one assigned

    Labels

    excluded: NOT_IMPORTABLEThis vulnerability only exists in a binary and is not importable.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions