VDB
KO
MEDIUM 6.1

GHSA-x7rv-cr6v-4vm4

Cross-site Scripting in loofah

Details

Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments.

Users are affected if running Loofah < 2.2.1, but only:

* when running on MRI or RBX, * in combination with libxml2 >= 2.9.2.

JRuby users are not affected.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / loofah
Introduced in: 0 Fixed in: 2.2.1
Fix bundle update loofah
RubyGems / nokogiri
Introduced in: 0 Fixed in: 1.8.3
Fix bundle update nokogiri

References