Логотип exploitDog
bind:"BDU:2025-04577" OR bind:"CVE-2024-53987"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-04577" OR bind:"CVE-2024-53987"

Количество 7

Количество 7

fstec логотип

BDU:2025-04577

около 1 года назад

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-53987

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "style" element is explicitly allowed and the "svg" or "math" element is not allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-53987

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "style" element is explicitly allowed and the "svg" or "math" element is not allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-53987

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "style" element is explicitly allowed and the "svg" or "math" element is not allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-53987

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2x5m-9ch4-qgrr

около 1 года назад

rails-html-sanitizer has XSS vulnerability with certain configurations

EPSS: Низкий
redos логотип

ROS-20250402-05

9 месяцев назад

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-04577

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-53987

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "style" element is explicitly allowed and the "svg" or "math" element is not allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-53987

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "style" element is explicitly allowed and the "svg" or "math" element is not allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-53987

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "style" element is explicitly allowed and the "svg" or "math" element is not allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-53987

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2x5m-9ch4-qgrr

rails-html-sanitizer has XSS vulnerability with certain configurations

0%
Низкий
около 1 года назад
redos логотип
ROS-20250402-05

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
9 месяцев назад

Уязвимостей на страницу