Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38485
HistoryDec 15, 2022 - 2:04 a.m.

Regular Expression Denial Of Service (ReDoS)

2022-12-1502:04:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
regular expression denial of service
rails-html-sanitizer
insecure regex pattern
attr_node.value attribute
scrubbers.rb
malicious svg attributes.

0.001 Low

EPSS

Percentile

36.5%

rails-html-sanitizer is vulnerable to regular expression denial of service. The vulnerability exists due to the insecure regex pattern used for the attr_node.value attribute in the scrub_attributes function of scrubbers.rb, allowing an attacker to crash the application by providing malicious SVG attributes.