GHSA-p4x4-rw2p-8j8m
Cross-site Scripting in Sanitize
Quick fix
GHSA-p4x4-rw2p-8j8m — sanitize: upgrade to the fixed version with the command below.
bundle update sanitizeDetails
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a `<math>` or `<svg>` element may not be sanitized correctly even if `math` and `svg` are not in the allowlist.
You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
- `iframe` - `math` - `noembed` - `noframes` - `noscript` - `plaintext` - `script` - `style` - `svg` - `xmp`
### Impact
Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser.
### Releases
This problem has been fixed in Sanitize 5.2.1.
### Workarounds
If upgrading is not possible, a workaround is to override the default value of Sanitize's `:remove_contents` config option with the following value, which ensures that the contents of `math` and `svg` elements (among others) are removed entirely when those elements are not in the allowlist:
```ruby %w[iframe math noembed noframes noscript plaintext script style svg xmp] ```
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of `:remove_contents` like this:
```ruby custom_config = Sanitize::Config.merge( Sanitize::Config::RELAXED, :remove_contents => %w[iframe math noembed noframes noscript plaintext script style svg xmp] ) ```
You would then pass this custom config to Sanitize when sanitizing HTML.
### For more information
If you have any questions or comments about this advisory:
- Open an issue in the [Sanitize repo](https://github.com/rgrove/sanitize). - See Sanitize's [security policy](https://github.com/rgrove/sanitize/security/policy).
### Credits
Many thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix.
### References
- [GHSA-p4x4-rw2p-8j8m](https://github.com/rgrove/sanitize/security/advisories/GHSA-p4x4-rw2p-8j8m) - [CVE-2020-4054](https://nvd.nist.gov/vuln/detail/CVE-2020-4054) - https://github.com/rgrove/sanitize/releases/tag/v5.2.1
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rgrove/sanitize/security/advisories/GHSA-p4x4-rw2p-8j8m[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-4054[ADVISORY]
- https://github.com/rgrove/sanitize/commit/a11498de9e283cd457b35ee252983662f7452aa9[WEB]
- https://github.com/rgrove/sanitize[PACKAGE]
- https://github.com/rgrove/sanitize/releases/tag/v5.2.1[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sanitize/CVE-2020-4054.yml[WEB]
- https://usn.ubuntu.com/4543-1[WEB]
- https://www.debian.org/security/2020/dsa-4730[WEB]