CRITICAL 9.8 Microsoft

CVE-2023-24538

Backticks not treated as string delimiters in html/template

Microsoft Security Update 2023-Apr: Backticks not treated as string delimiters in html/template

Affected Products

References

Published: 2023-04-11 · Source: Microsoft · Feed updated: 2026-09-17
This critical severity vulnerability with a CVSS score of 9.8 was published on 2023-04-11 via Microsoft. Affected: cbl2 golang 1.17.13-2 on CBL Mariner 2.0, cbl2 golang 1.21.6-1 on CBL Mariner 2.0, cbl2 msft-golang 1.20.11-1 on CBL Mariner 2.0 and 4 more.

Risk Timeline

CVE Disclosed2023-04-11 · 1254 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-49844 PoCRedis Lua Use-After-Free may lead to remote code executionCRITICAL9.9
CVE-2024-41110 PoCMoby authz zero length regressionCRITICAL9.9
CVE-2024-24790Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netipCRITICAL9.8
CVE-2024-39331In Emacs before 29.4 org-link-expand-abbrev in lisp/ol.el expands a %(...) link CRITICAL9.8
CVE-2024-4577 PoCArgument Injection in PHP-CGICRITICAL9.8
CVE-2024-38541of: module: add buffer overflow check in of_modalias()CRITICAL9.8
vulnfeed aggregates 8294 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.