| - module: github.com/kitabisa/teler-waf |
| - package: github.com/kitabisa/teler-waf |
| - Teler.checkCommonWebAttack |
| - Teler.HandlerFuncWithNext |
| summary: Arbitrary code execution in github.com/kitabisa/teler-waf |
| Improper handling of payload with special characters, such as CR/LF and |
| horizontal tab, can lead to execution of arbitrary JavaScript code. |
| - advisory: https://github.com/advisories/GHSA-p2pf-g8cq-3gq5 |
| - fix: https://github.com/kitabisa/teler-waf/commit/6e1b0e19b8adc1bbc3513a986025d4adf88d59f8 |
| - web: https://github.com/kitabisa/teler-waf/releases/tag/v0.2.0 |