golang.org/x/net CVE-2023-3978
Package
amazon-ssm-agent
(bottlerocket)
Affected versions
< 1.17.0
Patched versions
1.17.0
cni-plugins
(bottlerocket)
< 1.17.0
1.17.0
containerd
(bottlerocket)
< 1.17.0
1.17.0
ecs-agent
(bottlerocket)
< 1.17.0
1.17.0
nvidia-k8s-device-plugin
(bottlerocket)
< 1.17.0
1.17.0
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could allow for cross site scripting.