Lucene search

K
osvGoogleOSV:USN-4543-1
HistorySep 25, 2020 - 5:03 p.m.

ruby-sanitize vulnerability

2020-09-2517:03:04
Google
osv.dev
6
sanitize
michał bentkowski
xss
cve-2020-4054
html
svg
cross-site scripting
remote attacker
vulnerability

AI Score

6

Confidence

High

EPSS

0.001

Percentile

50.0%

Michał Bentkowski discovered that Sanitize did not properly sanitize some
math or svg HTML under certain circumstances. A remote attacker could
potentially exploit this to conduct cross-site scripting (XSS) attacks.
(CVE-2020-4054)

AI Score

6

Confidence

High

EPSS

0.001

Percentile

50.0%