CVE-2018-8048: XSS
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ruby-loofahto a version that resolves this vulnerability.Fixed in 2.2.3-1+deb10u1Fixed in 2.2.3-1+deb10u2Fixed in 2.7.0+dfsg-1Fixed in 2.19.1-1Fixed in 2.21.3-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8048?
The severity of CVE-2018-8048 is considered medium due to the potential exposure of non-whitelisted HTML attributes in sanitized output.
How do I fix CVE-2018-8048?
To fix CVE-2018-8048, update the Loofah gem to version 2.2.3 or later, or apply the relevant security patches provided by your distribution.
What versions of Loofah are affected by CVE-2018-8048?
CVE-2018-8048 affects Loofah gem versions up to and including 2.2.0.
What are the implications of not addressing CVE-2018-8048?
Not addressing CVE-2018-8048 may lead to security issues where malicious HTML attributes are improperly sanitized and included in applications.
Which software packages are vulnerable due to CVE-2018-8048?
The vulnerable software packages include ruby-loofah versions prior to 2.2.3, specifically in Debian distributions.