First published: Tue Mar 20 2018(Updated: )
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ruby-loofah | 2.2.3-1+deb10u1 2.2.3-1+deb10u2 2.7.0+dfsg-1 2.19.1-1 2.21.3-1 | |
Debian Debian Linux | =9.0 | |
Loofah Project Loofah | <2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.