PT-2019-5086 · Ruby+2 · Loofah+2
CVE-2019-15587
·
Publicado
2019-10-22
·
Atualizado
2026-03-13
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Loofah gem for Ruby versions through 2.3.0
Description
The issue is related to the Loofah gem for Ruby, where unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. This could potentially allow a remote attacker to impact data integrity by exploiting the vulnerability, which is associated with a lack of protection for the web page structure.
Recommendations
For Loofah gem for Ruby versions through 2.3.0, consider disabling the use of crafted SVG elements in the sanitization process until a patch is available. Restrict access to the sanitization module to minimize the risk of exploitation. Avoid using the Loofah gem for Ruby for sensitive data processing until the issue is resolved.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Loofah
Suse
Ubuntu