VDB
Sign up
MEDIUM6.1

GHSA-x7rv-cr6v-4vm4

Cross-site Scripting in loofah

Quick fix

GHSA-x7rv-cr6v-4vm4 — loofah: upgrade to the fixed version with the command below.

bundle update loofah

Details

Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments.

Users are affected if running Loofah < 2.2.1, but only:

* when running on MRI or RBX, * in combination with libxml2 >= 2.9.2.

JRuby users are not affected.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/loofah
Introduced in: 0Fixed in: 2.2.1
Fixbundle update loofah
RubyGems/nokogiri
Introduced in: 0Fixed in: 1.8.3
Fixbundle update nokogiri

References