VDB
Sign up
HIGH7.5

GHSA-7f42-p84j-f58p

Sanitize vulnerable to Improper Input Validation and Cross-site Scripting

Quick fix

GHSA-7f42-p84j-f58p — sanitize: upgrade to the fixed version with the command below.

bundle update sanitize

Details

When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements.

This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sanitize
Introduced in: 3.0.0Fixed in: 4.6.3
Fixbundle update sanitize

References