Логотип exploitDog
bind: "CVE-2024-53988"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-53988"

Количество 7

Количество 7

ubuntu логотип

CVE-2024-53988

больше 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-53988

больше 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-53988

больше 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-53988

больше 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cfjx-w229-hgx5

больше 1 года назад

rails-html-sanitizer has XSS vulnerability with certain configurations

EPSS: Низкий
fstec логотип

BDU:2025-04576

больше 1 года назад

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20250402-05

12 месяцев назад

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
2%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
2%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
2%
Низкий
больше 1 года назад
debian логотип
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

CVSS3: 6.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-cfjx-w229-hgx5

rails-html-sanitizer has XSS vulnerability with certain configurations

2%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-04576

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
2%
Низкий
больше 1 года назад
redos логотип
ROS-20250402-05

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
12 месяцев назад

Уязвимостей на страницу