Логотип exploitDog
bind: "CVE-2024-53986"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-53986"

Количество 7

Количество 7

ubuntu логотип

CVE-2024-53986

7 месяцев назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math" and "style" elements are both explicitly allowed. This vulnerability is fixed in 1.6.1.

EPSS: Низкий
redhat логотип

CVE-2024-53986

7 месяцев назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math" and "style" elements are both explicitly allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-53986

7 месяцев назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math" and "style" elements are both explicitly allowed. This vulnerability is fixed in 1.6.1.

EPSS: Низкий
debian логотип

CVE-2024-53986

7 месяцев назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

EPSS: Низкий
github логотип

GHSA-638j-pmjw-jq48

7 месяцев назад

rails-html-sanitizer has XSS vulnerability with certain configurations

EPSS: Низкий
fstec логотип

BDU:2025-04578

7 месяцев назад

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20250402-05

3 месяца назад

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-53986

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math" and "style" elements are both explicitly allowed. This vulnerability is fixed in 1.6.1.

0%
Низкий
7 месяцев назад
redhat логотип
CVE-2024-53986

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math" and "style" elements are both explicitly allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2024-53986

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math" and "style" elements are both explicitly allowed. This vulnerability is fixed in 1.6.1.

0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-53986

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

0%
Низкий
7 месяцев назад
github логотип
GHSA-638j-pmjw-jq48

rails-html-sanitizer has XSS vulnerability with certain configurations

0%
Низкий
7 месяцев назад
fstec логотип
BDU:2025-04578

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
0%
Низкий
7 месяцев назад
redos логотип
ROS-20250402-05

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
3 месяца назад

Уязвимостей на страницу