Description: Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution. Broken commit info: Bugfix commit info: https://github.com/golang/go/commit/a32232cb18ed07496ec77c1cf2dcefa1cb0ac057 https://github.com/golang/go/commit/ce7bd33345416e6d8cac901792060591cafc2797 https://github.com/golang/go/commit/4a28cad66655ee01c6e944271e23c33cab021765
https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU?pli=1 目前anolis 23中的版本是 golang-1.20.4,已经修复了 CVE-2023-24539, CVE-2023-24540, CVE-2023-29400