Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16468

Опубликовано: 27 окт. 2018
Источник: redhat
CVSS3: 5.4

Описание

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

Отчет

Red Hat Satellite 6 does not allow displaying user-defined SVGs and is thus not affected by this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-amazon-smartstateNot affected
CloudForms Management Engine 5cfme-gemsetNot affected
Red Hat Satellite 6tfm-ror51-rubygem-loofahWill not fix
Red Hat Software Collectionsrh-ror42-rubygem-loofahWill not fix
Red Hat Software Collectionsrh-ror50-rubygem-loofahWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1646715rubygem-loofah: XXS when a crafted SVG element is republished

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 7 лет назад

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

CVSS3: 5.4
nvd
больше 7 лет назад

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

CVSS3: 5.4
debian
больше 7 лет назад

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may ...

suse-cvrf
около 7 лет назад

Security update for rubygem-loofah

suse-cvrf
около 7 лет назад

Security update for rubygem-loofah

5.4 Medium

CVSS3

Уязвимость CVE-2018-16468