6.8

CVE-2020-29510

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Golang ≫ Go Version <= 1.15
Netapp ≫ Trident Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.05% 0.787
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.6 2.2 3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
responsibledisclosure@mattermost.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-115 Misinterpretation of Input

The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.

https://security.netapp.com/advisory/ntap-20210129-0006/
Third Party Advisory
https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-directives.md
Third Party Advisory