Medium severity6.1NVD Advisory· Published Sep 2, 2020· Updated Jun 17, 2026
CVE-2020-24553
CVE-2020-24553
Description
Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html is the default for CGI/FCGI handlers that lack a Content-Type header.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- Go/Godescription
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.5.0:*:*:*:*:*:*:*
- osv-coords9 versionspkg:rpm/opensuse/go1.15&distro=openSUSE%20Tumbleweedpkg:bitnami/golangpkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP1pkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP1pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/opensuse/go1.14&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.14&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/go1.14&distro=openSUSE%20Tumbleweed
< 1.15.15-1.2+ 8 more
- (no CPE)range: < 1.15.15-1.2
- (no CPE)range: < 1.14.8
- (no CPE)range: < 1.14.9-1.18.1
- (no CPE)range: < 1.14.9-1.18.1
- (no CPE)range: < 1.15.2-1.3.1
- (no CPE)range: < 1.15.2-1.3.1
- (no CPE)range: < 1.14.9-lp152.2.6.1
- (no CPE)range: < 1.14.9-lp151.16.1
- (no CPE)range: < 1.14.15-1.6
Patches
Vulnerability mechanics
References
10- www.oracle.com//security-alerts/cpujul2021.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpuApr2021.htmlnvdPatchThird Party Advisory
- packetstormsecurity.com/files/159049/Go-CGI-FastCGI-Transport-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2020/Sep/5nvdExploitMailing ListThird Party Advisory
- www.redteam-pentesting.de/advisories/rt-sa-2020-004nvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-10/msg00000.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-10/msg00002.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20200924-0003/nvdThird Party Advisory
- groups.google.com/forum/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CZBO7Q73GGWBVYIKNH2HNN44Q5IQND5W/nvd
News mentions
0No linked articles in our index yet.