Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x7rv-cr6v-4vm4

Опубликовано: 21 мар. 2018
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site Scripting in loofah

Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments.

Users are affected if running Loofah < 2.2.1, but only:

  • when running on MRI or RBX,
  • in combination with libxml2 >= 2.9.2.

JRuby users are not affected.

Пакеты

Наименование

loofah

rubygems
Затронутые версииВерсия исправления

< 2.2.1

2.2.1

Наименование

nokogiri

rubygems
Затронутые версииВерсия исправления

< 1.8.3

1.8.3

EPSS

Процентиль: 73%
0.0076
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 8 лет назад

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

CVSS3: 6.1
redhat
почти 8 лет назад

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

CVSS3: 6.1
nvd
почти 8 лет назад

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

CVSS3: 6.1
debian
почти 8 лет назад

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attribu ...

EPSS

Процентиль: 73%
0.0076
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79