Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:0356-1

Опубликовано: 07 фев. 2016
Источник: suse-cvrf

Описание

Security update for rubygem-rails-html-sanitizer

This update for rubygem-rails-html-sanitizer fixes the following issues:

  • CVE-2015-7579: XSS vulnerability in rails-html-sanitizer (bsc#963327)
  • CVE-2015-7578: XSS vulnerability via attributes (bsc#963326)
  • CVE-2015-7580: XSS via whitelist sanitizer (bsc#963328)

Список пакетов

openSUSE Leap 42.1
ruby2.1-rubygem-rails-html-sanitizer-1.0.2-5.1
ruby2.1-rubygem-rails-html-sanitizer-doc-1.0.2-5.1
ruby2.1-rubygem-rails-html-sanitizer-testsuite-1.0.2-5.1
rubygem-rails-html-sanitizer-1.0.2-5.1

Описание

Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes.


Затронутые продукты
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-1.0.2-5.1
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-doc-1.0.2-5.1
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-testsuite-1.0.2-5.1
openSUSE Leap 42.1:rubygem-rails-html-sanitizer-1.0.2-5.1

Ссылки

Описание

Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class.


Затронутые продукты
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-1.0.2-5.1
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-doc-1.0.2-5.1
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-testsuite-1.0.2-5.1
openSUSE Leap 42.1:rubygem-rails-html-sanitizer-1.0.2-5.1

Ссылки

Описание

Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.


Затронутые продукты
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-1.0.2-5.1
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-doc-1.0.2-5.1
openSUSE Leap 42.1:ruby2.1-rubygem-rails-html-sanitizer-testsuite-1.0.2-5.1
openSUSE Leap 42.1:rubygem-rails-html-sanitizer-1.0.2-5.1

Ссылки