Логотип exploitDog
bind:CVE-2023-36823
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-36823

Количество 5

Количество 5

ubuntu логотип

CVE-2023-36823

больше 2 лет назад

Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or more CSS at-rules. This could result in cross-site scripting or other undesired behavior when the malicious HTML and CSS are rendered in a browser. Sanitize 6.0.2 performs additional escaping of CSS in `style` element content, which fixes this issue. Users who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow `style` elements, using a Sanitize config that doesn't allow CSS at-rules, or by manually escaping the character sequence `</` as `<\/` in `style` element content.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2023-36823

больше 2 лет назад

Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or more CSS at-rules. This could result in cross-site scripting or other undesired behavior when the malicious HTML and CSS are rendered in a browser. Sanitize 6.0.2 performs additional escaping of CSS in `style` element content, which fixes this issue. Users who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow `style` elements, using a Sanitize config that doesn't allow CSS at-rules, or by manually escaping the character sequence `</` as `<\/` in `style` element content.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2023-36823

больше 2 лет назад

Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-f5ww-cq3m-q3g7

больше 2 лет назад

Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2024-02630

больше 2 лет назад

Уязвимость компонента Sanitize::Config::RELAXED библиотеки Sanitize для языка программирования Ruby, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-36823

Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or more CSS at-rules. This could result in cross-site scripting or other undesired behavior when the malicious HTML and CSS are rendered in a browser. Sanitize 6.0.2 performs additional escaping of CSS in `style` element content, which fixes this issue. Users who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow `style` elements, using a Sanitize config that doesn't allow CSS at-rules, or by manually escaping the character sequence `</` as `<\/` in `style` element content.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-36823

Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or more CSS at-rules. This could result in cross-site scripting or other undesired behavior when the malicious HTML and CSS are rendered in a browser. Sanitize 6.0.2 performs additional escaping of CSS in `style` element content, which fixes this issue. Users who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow `style` elements, using a Sanitize config that doesn't allow CSS at-rules, or by manually escaping the character sequence `</` as `<\/` in `style` element content.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-36823

Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully ...

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-f5ww-cq3m-q3g7

Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-02630

Уязвимость компонента Sanitize::Config::RELAXED библиотеки Sanitize для языка программирования Ruby, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 7.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу