Vulnerability CVE-2018-16468: Information

Description

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

Severity: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Published: Oct. 31, 2018
Modified: Oct. 10, 2019
Error type identifier: CWE-79

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
ruby-loofahp92.2.3-alt12.2.3-alt1ALT-PU-2019-1536-1225783Fixed
ruby-loofahc10f12.2.3-alt12.2.3-alt1ALT-PU-2019-1536-1225783Fixed
ruby-loofahc9f22.2.3-alt12.2.3-alt1ALT-PU-2019-1536-1225783Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://github.com/flavorjones/loofah/issues/154
  • Third Party Advisory
DSA-4364
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:loofah_project:loofah:*:*:*:*:*:ruby:*:*
      End including
      2.2.2

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*