MEDIUM 6.1 RubyGems

Cross-site Scripting in loofah

GHSA-x7rv-cr6v-4vm4 · CVE-2018-8048

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments.

Users are affected if running Loofah < 2.2.1, but only:

  • when running on MRI or RBX,
  • in combination with libxml2 >= 2.9.2.

JRuby users are not affected.

Ready to move

Start Securing

Free, no credit card | First findings in minutes