Логотип exploitDog
bind:CVE-2024-53985
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-53985

Количество 7

Количество 7

ubuntu логотип

CVE-2024-53985

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags with both "math" and "style" elements or both both "svg" and "style" elements. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-53985

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags with both "math" and "style" elements or both both "svg" and "style" elements. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-53985

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags with both "math" and "style" elements or both both "svg" and "style" elements. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-53985

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-w8gc-x259-rc7x

около 1 года назад

rails-html-sanitize has XSS vulnerability with certain configurations

EPSS: Низкий
fstec логотип

BDU:2025-04579

около 1 года назад

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20250402-05

9 месяцев назад

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-53985

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags with both "math" and "style" elements or both both "svg" and "style" elements. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-53985

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags with both "math" and "style" elements or both both "svg" and "style" elements. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-53985

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags with both "math" and "style" elements or both both "svg" and "style" elements. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-53985

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-w8gc-x259-rc7x

rails-html-sanitize has XSS vulnerability with certain configurations

0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-04579

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
0%
Низкий
около 1 года назад
redos логотип
ROS-20250402-05

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
9 месяцев назад

Уязвимостей на страницу