Lucene search

K
osvGoogleOSV:USN-4498-1
HistorySep 15, 2020 - 7:25 p.m.

ruby-loofah vulnerability

2020-09-1519:25:01
Google
osv.dev
5

6.7 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.1%

It was discovered that Loofah does not properly sanitize JavaScript in
sanitized output. An attacker could possibly use this issue to perform
XSS attacks. (CVE-2019-15587)