Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian Buster: DLA-3566-1 Critical: HTML Sanitizer XSS And DoS Risks

debian lts
Calendar Grey September 13, 2023
Dist Debian Esm H88
Several security flaws in ruby-rails-html-sanitizer have been addressed. It's advisable to upgrade promptly to mitigate against XSS and DoS threats.
Multiple vulnerabilities were discovered in Rails HTML Sanitizers, an HTML sanitization library for Ruby on Rails applications

Summary

CVE-2022-23517

Certain configurations use an inefficient regular expression that
is susceptible to excessive backtracking when attempting to
sanitize certain SVG attributes. This may lead to a denial of
service through CPU resource consumption.

CVE-2022-23518

Cross-site scripting via data URIs when used in combination with
Loofah >= 2.1.0.

CVE-2022-23519

XSS vulnerability with certain configurations of
Rails::Html::Sanitizer may allow an attacker to inject content if
the application developer has overridden the sanitizer's allowed
tags in either of the following ways: allow both "math" and
"style" elements, or allow both "svg" and "style" elements.

CVE-2022-23520

XSS vulnerability with certain configurations of
Rails::Html::Sanitizer due to an incomplete fix of
CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to
inject content if the application developer has overridden the

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: ruby-rails-html-sanitizer
Version: 1.0.4-1+deb10u2
CVE ID: CVE-2022-23517 CVE-2022-23518 CVE-2022-23519 CVE-2022-23520
Debian Bug: 1027153

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here