Количество 6
Количество 6

CVE-2022-23515
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.

CVE-2022-23515
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.

CVE-2022-23515
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.
CVE-2022-23515
Loofah is a general library for manipulating and transforming HTML/XML ...
GHSA-228g-948r-83gx
Improper neutralization of data URIs may allow XSS in Loofah

SUSE-SU-2023:1657-1
Security update for rubygem-loofah
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2022-23515 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2022-23515 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2022-23515 Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад |
CVE-2022-23515 Loofah is a general library for manipulating and transforming HTML/XML ... | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-228g-948r-83gx Improper neutralization of data URIs may allow XSS in Loofah | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
![]() | SUSE-SU-2023:1657-1 Security update for rubygem-loofah | около 2 лет назад |
Уязвимостей на страницу