Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.20.3-1ubuntu0.1~20.04", "binary_name": "golang-1.20" }, { "binary_version": "1.20.3-1ubuntu0.1~20.04", "binary_name": "golang-1.20-doc" }, { "binary_version": "1.20.3-1ubuntu0.1~20.04", "binary_name": "golang-1.20-go" }, { "binary_version": "1.20.3-1ubuntu0.1~20.04", "binary_name": "golang-1.20-go-dbgsym" }, { "binary_version": "1.20.3-1ubuntu0.1~20.04", "binary_name": "golang-1.20-src" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.20.3-1ubuntu0.1~22.04", "binary_name": "golang-1.20" }, { "binary_version": "1.20.3-1ubuntu0.1~22.04", "binary_name": "golang-1.20-doc" }, { "binary_version": "1.20.3-1ubuntu0.1~22.04", "binary_name": "golang-1.20-go" }, { "binary_version": "1.20.3-1ubuntu0.1~22.04", "binary_name": "golang-1.20-go-dbgsym" }, { "binary_version": "1.20.3-1ubuntu0.1~22.04", "binary_name": "golang-1.20-src" } ] }