Логотип exploitDog
bind:CVE-2024-53988
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-53988

Количество 7

Количество 7

ubuntu логотип

CVE-2024-53988

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-53988

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-53988

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-53988

около 1 года назад

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cfjx-w229-hgx5

около 1 года назад

rails-html-sanitizer has XSS vulnerability with certain configurations

EPSS: Низкий
fstec логотип

BDU:2025-04576

около 1 года назад

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20250402-05

9 месяцев назад

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 3.1
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "math", "mtext", "table", and "style" elements are allowed and either either "mglyph" or "malignmark" are allowed. This vulnerability is fixed in 1.6.1.

CVSS3: 6.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-53988

rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-cfjx-w229-hgx5

rails-html-sanitizer has XSS vulnerability with certain configurations

0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-04576

Уязвимость реализации конфигурации инструмента очистки HTML для приложений Rails Html Sanitizer, позволяющая нарушителю проводить межсайтовые сценарные атаки

CVSS3: 6.5
0%
Низкий
около 1 года назад
redos логотип
ROS-20250402-05

Множественные уязвимости rubygem-rails-html-sanitizer

CVSS3: 6.5
9 месяцев назад

Уязвимостей на страницу