Loading HuntDB...

CVE-2018-3741

UNKNOWN
Published 2018-03-30T19:00:00
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2018-3741. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed MODERATE

rails-html-sanitizer Cross-site Scripting vulnerability

GHSA-px3r-jm9g-c8w8

Advisory Details

There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.

Affected Packages

RubyGems rails-html-sanitizer
ECOSYSTEM: ≥0 <1.0.4

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Advisory provided by GitHub Security Advisory Database. Published: April 26, 2018, Modified: March 1, 2023

References

Published: 2018-03-30T19:00:00
Last Modified: 2024-08-05T04:50:30.644Z
Copied to clipboard!