First published: Tue Oct 22 2019(Updated: )
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
rubygems/loofah | <2.3.1 | 2.3.1 |
debian/ruby-loofah | <=2.0.3-1<=2.0.3-2+deb9u2<=2.2.3-1 | 2.3.1+dfsg-1 2.2.3-1+deb10u1 2.0.3-2+deb9u3 |
Loofah Project Loofah | <=2.3.0 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Canonical Ubuntu Linux | =16.04 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
ubuntu/ruby-loofah | <2.0.3-2+ | 2.0.3-2+ |
debian/ruby-loofah | 2.2.3-1+deb10u1 2.2.3-1+deb10u2 2.7.0+dfsg-1 2.19.1-1 2.22.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.