First published: Tue Oct 30 2018(Updated: )
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Loofah Project Loofah | <=2.2.2 | |
Debian Debian Linux | =9.0 | |
debian/ruby-loofah | 2.2.3-1+deb10u1 2.2.3-1+deb10u2 2.7.0+dfsg-1 2.19.1-1 2.21.3-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.