Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-3740

Опубликовано: 30 мар. 2018
Источник: debian

Описание

A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-sanitizefixed4.6.5-1experimentalpackage
ruby-sanitizefixed4.6.6-1package
ruby-sanitizeignoredjessiepackage

Примечания

  • https://github.com/rgrove/sanitize/issues/176

  • https://github.com/rgrove/sanitize/commit/01629a162e448a83d901456d0ba8b65f3b03d46e (v4.6.3)

  • Fixes for 2.1.x: https://github.com/rgrove/sanitize/compare/v2.1.0...v2.1.1

  • Only an issue in combination with libxml2 >= 2.9.2

  • The 'fragment' method was renamed from 'clean' method in earlier version

  • in v3.0.0

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.

CVSS3: 7.5
nvd
почти 8 лет назад

A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.

CVSS3: 7.5
github
почти 8 лет назад

Sanitize vulnerable to Improper Input Validation and Cross-site Scripting

CVSS3: 7.5
fstec
почти 8 лет назад

Уязвимость библиотеки Sanitize для языка программирования Ruby, позволяющая нарушителю обойти заданные ограничения на использование HTML атрибутов