HIGH7.5
GHSA-7f42-p84j-f58p
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
Quick fix
GHSA-7f42-p84j-f58p — sanitize: upgrade to the fixed version with the command below.
bundle update sanitizeDetails
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements.
This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3740[ADVISORY]
- https://github.com/rgrove/sanitize/issues/176[WEB]
- https://github.com/rgrove/sanitize/commit/01629a162e448a83d901456d0ba8b65f3b03d46e[WEB]
- https://github.com/rgrove/sanitize/commit/93feeb38e21864146bb29191792b971dbe1ec62e[WEB]
- https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released[WEB]
- https://github.com/rgrove/sanitize[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sanitize/CVE-2018-3740.yml[WEB]
- https://www.debian.org/security/2018/dsa-4358[WEB]