CVE-2019-15587: XSS
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Other sources
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15587?
CVE-2019-15587 is considered a medium severity vulnerability due to the risk of unsanitized JavaScript executing in sanitized output.
How do I fix CVE-2019-15587?
To fix CVE-2019-15587, upgrade the Loofah gem to version 2.3.1 or later.
Which versions of Loofah are affected by CVE-2019-15587?
Versions of Loofah gem through v2.3.0 are affected by CVE-2019-15587.
What type of vulnerability is CVE-2019-15587?
CVE-2019-15587 is a Cross-Site Scripting (XSS) vulnerability due to improper sanitization of SVG elements.
What software is impacted by CVE-2019-15587?
CVE-2019-15587 affects the Loofah gem for Ruby and related packages in Debian and Ubuntu distributions.