CVE-2022-23517
Certain configurations use an inefficient regular expression that
is susceptible to excessive backtracking when attempting to
sanitize certain SVG attributes. This may lead to a denial of
service through CPU resource consumption.
CVE-2022-23518
Cross-site scripting via data URIs when used in combination with
Loofah >= 2.1.0.
CVE-2022-23519
XSS vulnerability with certain configurations of
Rails::Html::Sanitizer may allow an attacker to inject content if
the application developer has overridden the sanitizer's allowed
tags in either of the following ways: allow both "math" and
"style" elements, or allow both "svg" and "style" elements.
CVE-2022-23520
XSS vulnerability with certain configurations of
Rails::Html::Sanitizer due to an incomplete fix of
CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to
inject content if the application developer has overridden the
Get the latest Linux and open source security news straight to your inbox.