[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4358-1 ruby-sanitize -- ruby-sanitize

ID: oval:org.secpod.oval:def:603596Date: (C)2019-01-03   (M)2021-09-11
Class: PATCHFamily: unix




The Shopify Application Security Team discovered that ruby-sanitize, a whitelist-based HTML sanitizer, is prone to a HTML injection vulnerability. A specially crafted HTML fragment can cause to allow non- whitelisted attributes to be used on a whitelisted HTML element.

Platform:
Debian 9.x
Product:
ruby-sanitize
Reference:
DSA-4358-1
CVE-2018-3740
CVE    1
CVE-2018-3740
CPE    2
cpe:/o:debian:debian_linux:9.x
cpe:/a:github:ruby-sanitize

© SecPod Technologies