CVE-2018-16468: XSS
Published Oct 30, 2018
·Updated
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Affected Software
3 affected componentsFixes available
debian/ruby-loofah
2.2.3-1+deb10u12.2.3-1+deb10u22.7.0+dfsg-12.19.1-12.21.3-1
Loofah Project Loofah Ruby<=2.2.2
Debian Debian Linux=9.0
Event History
Oct 30, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-16468?
CVE-2018-16468 has been rated as a high severity vulnerability due to the potential for unsanitized JavaScript in sanitized output.
2
How do I fix CVE-2018-16468?
To fix CVE-2018-16468, upgrade to Loofah versions 2.2.3 or higher, as these versions address the vulnerability.
3
Which versions of Loofah are affected by CVE-2018-16468?
CVE-2018-16468 affects all Loofah gem versions up to and including 2.2.2.
4
What platforms are impacted by CVE-2018-16468?
CVE-2018-16468 impacts applications using the Loofah gem on Ruby, particularly those running on Debian GNU/Linux 9.0.
5
Is there a workaround for CVE-2018-16468?
There are no widely recognized workarounds for CVE-2018-16468 other than upgrading to the patched versions.