Описание
Loofah Allows Cross-site Scripting
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-15587
- https://github.com/flavorjones/loofah/issues/171
- https://github.com/flavorjones/loofah/commit/0c6617af440879ce97440f6eb6c58636456dc8ec
- https://hackerone.com/reports/709009
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/loofah/CVE-2019-15587.yml
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4WK2UG7ORKRQOJ6E4XJ2NVIHYJES6BYZ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XMCWPLYPNIWYAY443IZZJ4IHBBLIHBP5
- https://security.netapp.com/advisory/ntap-20191122-0003
- https://usn.ubuntu.com/4498-1
- https://www.debian.org/security/2019/dsa-4554
Пакеты
Наименование
loofah
rubygems
Затронутые версииВерсия исправления
< 2.3.1
2.3.1
Связанные уязвимости
CVSS3: 5.4
ubuntu
больше 6 лет назад
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVSS3: 4.6
redhat
больше 6 лет назад
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVSS3: 5.4
nvd
больше 6 лет назад
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVSS3: 5.4
debian
больше 6 лет назад
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may o ...