Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-15587

Опубликовано: 22 окт. 2019
Источник: debian
EPSS Низкий

Описание

In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-loofahfixed2.3.1+dfsg-1package

Примечания

  • https://github.com/flavorjones/loofah/issues/171

EPSS

Процентиль: 73%
0.01561
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 7 лет назад

In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

CVSS3: 4.6
redhat
почти 7 лет назад

In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

CVSS3: 5.4
nvd
почти 7 лет назад

In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

suse-cvrf
почти 4 года назад

Security update for rubygem-loofah

CVSS3: 5.4
github
почти 7 лет назад

Loofah Allows Cross-site Scripting

EPSS

Процентиль: 73%
0.01561
Низкий