CVE-2018-3740
published 2018-03-30CVE-2018-3740: A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.52%
72.1th percentile
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-sanitize | < ruby-sanitize 4.6.6-1 (bookworm) | ruby-sanitize 4.6.6-1 (bookworm) |
| ryan_grove | sanitize | < 4.6.3 | 4.6.3 |
| sanitize_project | sanitize | <= 4.6.0 | — |
| sanitize_project | sanitize | >= 3.0.0 < 4.6.3 | 4.6.3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-hwe, linux-azure, linux-gcp vulnerabilities
osv·2018-08-14·CVSS 5.6
linux-hwe, linux-azure, linux-gcp vulnerabilities
linux-hwe, linux-azure, linux-gcp vulnerabilities
USN-3740-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerability is also known as L1 Terminal Fault (L1TF). A local
attacker in a guest virtual machine could use this to expose sensitive
information (memory from other guests or the host OS). (CVE-2018-3646)
It was discovered that memory present in the L1 data cache of an Intel CPU
core may be exposed to a malicious process that is executing on the CPU
core. This vulnerabili
OSV
CVE-2018-3740: A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element
osv·2018-03-30·CVSS 7.5
CVE-2018-3740 [HIGH] CVE-2018-3740: A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
GHSA
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
ghsa·2018-03-21
CVE-2018-3740 [HIGH] CWE-20 Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
When Sanitize = 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements.
This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers.
OSV
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
osv·2018-03-21
CVE-2018-3740 [HIGH] Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
When Sanitize = 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements.
This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers.
Debian
CVE-2018-3740: ruby-sanitize - A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-w...
vendor_debian·2018·CVSS 7.5
CVE-2018-3740 [HIGH] CVE-2018-3740: ruby-sanitize - A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-w...
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.
Scope: local
bookworm: resolved (fixed in 4.6.6-1)
bullseye: resolved (fixed in 4.6.6-1)
forky: resolved (fixed in 4.6.6-1)
sid: resolved (fixed in 4.6.6-1)
trixie: resolved (fixed in 4.6.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-3740 rubygem-sanitize: Improper filtering by libxml2 allows for cross-site scripting (XSS) [fedora-all]
bugzilla·2018-03-22·CVSS 7.5
CVE-2018-3740 [HIGH] CVE-2018-3740 rubygem-sanitize: Improper filtering by libxml2 allows for cross-site scripting (XSS) [fedora-all]
CVE-2018-3740 rubygem-sanitize: Improper filtering by libxml2 allows for cross-site scripting (XSS) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-3740 rubygem-sanitize: Improper filtering by libxml2 allows for cross-site scripting (XSS)
bugzilla·2018-03-22·CVSS 7.5
CVE-2018-3740 [HIGH] CVE-2018-3740 rubygem-sanitize: Improper filtering by libxml2 allows for cross-site scripting (XSS)
CVE-2018-3740 rubygem-sanitize: Improper filtering by libxml2 allows for cross-site scripting (XSS)
rubygem-sanitize before version 4.6.3 is vulnerable to a HTML injection vulnerability when used with libxml2 from version 2.9.2. An attacker could exploit this to perfrom a cross-site scripting attack (XSS).
External References:
https://github.com/rgrove/sanitize/issues/176
http://seclists.org/oss-sec/2018/q1/254
Upstream Patch:
https://github.com/rgrove/sanitize/commit/01629a162e448a83d901456d0ba8b65f3b03d46e
Discussion:
Created rubygem-sanitize tracking bugs for this issue:
Affects: fedora-all [bug 1559251]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the de
https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/https://github.com/rgrove/sanitize/commit/01629a162e448a83d901456d0ba8b65f3b03d46ehttps://github.com/rgrove/sanitize/issues/176https://www.debian.org/security/2018/dsa-4358https://about.gitlab.com/2018/06/25/security-release-gitlab-11-dot-0-dot-1-released/https://github.com/rgrove/sanitize/commit/01629a162e448a83d901456d0ba8b65f3b03d46ehttps://github.com/rgrove/sanitize/issues/176https://www.debian.org/security/2018/dsa-4358
2018-03-30
Published