Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23515

Опубликовано: 14 дек. 2022
Источник: debian
EPSS Низкий

Описание

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-loofahfixed2.19.1-1package

Примечания

  • https://github.com/flavorjones/loofah/security/advisories/GHSA-228g-948r-83gx

  • https://github.com/flavorjones/loofah/commit/415677f3cf7f9254f42f811e784985cd63c7407f

EPSS

Процентиль: 45%
0.00217
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 2 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.

CVSS3: 6.1
redhat
больше 2 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.

CVSS3: 6.1
nvd
больше 2 лет назад

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.

CVSS3: 6.1
github
больше 2 лет назад

Improper neutralization of data URIs may allow XSS in Loofah

suse-cvrf
около 2 лет назад

Security update for rubygem-loofah

EPSS

Процентиль: 45%
0.00217
Низкий