Lucene search

K
osvGoogleOSV:GHSA-X7RV-CR6V-4VM4
HistoryMar 21, 2018 - 11:57 a.m.

Cross-site Scripting in loofah

2018-03-2111:57:11
Google
osv.dev
15

0.002 Low

EPSS

Percentile

59.1%

Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments.

Users are affected if running Loofah < 2.2.1, but only:

  • when running on MRI or RBX,
  • in combination with libxml2 >= 2.9.2.

JRuby users are not affected.