CVE-2020-4054
published 2020-06-16CVE-2020-4054: In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulnerability. When HTML is sanitized using…
PriorityP338high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
1.85%
77.1th percentile
In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulnerability. When HTML is sanitized using Sanitize's "relaxed" config, or a custom config that allows certain elements, some content in a math or svg element may not be sanitized correctly even if math and svg are not in the allowlist. You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements: iframe, math, noembed, noframes, noscript, plaintext, script, style, svg, xmp. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. This has been fixed in 5.2.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-sanitize | < ruby-sanitize 4.6.6-2.1 (bookworm) | ruby-sanitize 4.6.6-2.1 (bookworm) |
| rgrove | sanitize | — | — |
| sanitize_project | sanitize | >= 3.0.0 < 5.2.1 | 5.2.1 |
| sanitize_project | sanitize | >= 3.0.0 < 5.2.1 | 5.2.1 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.3HIGH
vendor_debian7.3HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ruby-sanitize vulnerability
osv·2020-09-25·CVSS 7.3
CVE-2020-4054 [HIGH] ruby-sanitize vulnerability
ruby-sanitize vulnerability
Michał Bentkowski discovered that Sanitize did not properly sanitize some
math or svg HTML under certain circumstances. A remote attacker could
potentially exploit this to conduct cross-site scripting (XSS) attacks.
(CVE-2020-4054)
OSV
CVE-2020-4054: In Sanitize (RubyGem sanitize) greater than or equal to 3
osv·2020-06-16·CVSS 7.3
CVE-2020-4054 [HIGH] CVE-2020-4054: In Sanitize (RubyGem sanitize) greater than or equal to 3
In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulnerability. When HTML is sanitized using Sanitize's "relaxed" config, or a custom config that allows certain elements, some content in a math or svg element may not be sanitized correctly even if math and svg are not in the allowlist. You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements: iframe, math, noembed, noframes, noscript, plaintext, script, style, svg, xmp. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a b
OSV
Cross-site Scripting in Sanitize
osv·2020-06-16
CVE-2020-4054 [HIGH] Cross-site Scripting in Sanitize
Cross-site Scripting in Sanitize
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a `` or `` element may not be sanitized correctly even if `math` and `svg` are not in the allowlist.
You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
- `iframe`
- `math`
- `noembed`
- `noframes`
- `noscript`
- `plaintext`
- `script`
- `style`
- `svg`
- `xmp`
### Impact
Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser.
### Releases
This problem has been fixed
GHSA
Cross-site Scripting in Sanitize
ghsa·2020-06-16
CVE-2020-4054 [HIGH] CWE-79 Cross-site Scripting in Sanitize
Cross-site Scripting in Sanitize
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a `` or `` element may not be sanitized correctly even if `math` and `svg` are not in the allowlist.
You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
- `iframe`
- `math`
- `noembed`
- `noframes`
- `noscript`
- `plaintext`
- `script`
- `style`
- `svg`
- `xmp`
### Impact
Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser.
### Releases
This problem has been fixed
Ubuntu
Sanitize vulnerability
vendor_ubuntu·2020-09-25·CVSS 7.3
CVE-2020-4054 [HIGH] Sanitize vulnerability
Title: Sanitize vulnerability
Summary: Sanitize could be made to perform XSS attacks if it received specially
crafted input.
Michał Bentkowski discovered that Sanitize did not properly sanitize some
math or svg HTML under certain circumstances. A remote attacker could
potentially exploit this to conduct cross-site scripting (XSS) attacks.
(CVE-2020-4054)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-4054: ruby-sanitize - In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2....
vendor_debian·2020·CVSS 7.3
CVE-2020-4054 [HIGH] CVE-2020-4054: ruby-sanitize - In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2....
In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulnerability. When HTML is sanitized using Sanitize's "relaxed" config, or a custom config that allows certain elements, some content in a math or svg element may not be sanitized correctly even if math and svg are not in the allowlist. You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements: iframe, math, noembed, noframes, noscript, plaintext, script, style, svg, xmp. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a b
Suricata
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template INSERT
suricata·2010-07-30·CVSS 6.8
CVE-2007-3214 [MEDIUM] ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template INSERT
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template INSERT"; flow:established,to_server; http.uri; content:"/style.php?"; nocase; content:"template="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-3214; reference:url,www.milw0rm.com/exploits/4054; classtype:web-application-attack; sid:2005338; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_tec
Suricata
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template UPDATE
suricata·2010-07-30·CVSS 6.8
CVE-2007-3214 [MEDIUM] ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template UPDATE
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template UPDATE"; flow:established,to_server; http.uri; content:"/style.php?"; nocase; content:"template="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-3214; reference:url,www.milw0rm.com/exploits/4054; classtype:web-application-attack; sid:2005341; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_tech
Suricata
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template ASCII
suricata·2010-07-30·CVSS 6.8
CVE-2007-3214 [MEDIUM] ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template ASCII
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template ASCII"; flow:established,to_server; http.uri; content:"/style.php?"; nocase; content:"template="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-3214; reference:url,www.milw0rm.com/exploits/4054; classtype:web-application-attack; sid:2005340; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_tec
Suricata
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template SELECT
suricata·2010-07-30·CVSS 6.8
CVE-2007-3214 [MEDIUM] ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template SELECT
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template SELECT"; flow:established,to_server; http.uri; content:"/style.php?"; nocase; content:"template="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-3214; reference:url,www.milw0rm.com/exploits/4054; classtype:web-application-attack; sid:2005336; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_tec
Suricata
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template DELETE
suricata·2010-07-30·CVSS 6.8
CVE-2007-3214 [MEDIUM] ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template DELETE
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template DELETE"; flow:established,to_server; http.uri; content:"/style.php?"; nocase; content:"template="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-3214; reference:url,www.milw0rm.com/exploits/4054; classtype:web-application-attack; sid:2005339; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_tec
Suricata
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template UNION SELECT
suricata·2010-07-30·CVSS 6.8
CVE-2007-3214 [MEDIUM] ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template UNION SELECT
ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS e-Vision CMS SQL Injection Attempt -- style.php template UNION SELECT"; flow:established,to_server; http.uri; content:"/style.php?"; nocase; content:"template="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-3214; reference:url,www.milw0rm.com/exploits/4054; classtype:web-application-attack; sid:2005337; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Acce
Bugzilla
CVE-2020-4054 rubygem-rails-html-sanitizer: XSS via crafted input
bugzilla·2020-06-19·CVSS 6.1
CVE-2020-4054 [MEDIUM] CVE-2020-4054 rubygem-rails-html-sanitizer: XSS via crafted input
CVE-2020-4054 rubygem-rails-html-sanitizer: XSS via crafted input
In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulnerability. When HTML is sanitized using Sanitize's "relaxed" config, or a custom config that allows certain elements, some content in a math or svg element may not be sanitized correctly even if math and svg are not in the allowlist. You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements: iframe, math, noembed, noframes, noscript, plaintext, script, style, svg, xmp. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scrip
Bugzilla
CVE-2020-4054 rubygem-rails-html-sanitizer: XSS via crafted input [fedora-all]
bugzilla·2020-06-19·CVSS 7.3
CVE-2020-4054 [HIGH] CVE-2020-4054 rubygem-rails-html-sanitizer: XSS via crafted input [fedora-all]
CVE-2020-4054 rubygem-rails-html-sanitizer: XSS via crafted input [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
https://github.com/rgrove/sanitize/commit/a11498de9e283cd457b35ee252983662f7452aa9https://github.com/rgrove/sanitize/releases/tag/v5.2.1https://github.com/rgrove/sanitize/security/advisories/GHSA-p4x4-rw2p-8j8mhttps://usn.ubuntu.com/4543-1/https://www.debian.org/security/2020/dsa-4730https://github.com/rgrove/sanitize/commit/a11498de9e283cd457b35ee252983662f7452aa9https://github.com/rgrove/sanitize/releases/tag/v5.2.1https://github.com/rgrove/sanitize/security/advisories/GHSA-p4x4-rw2p-8j8mhttps://usn.ubuntu.com/4543-1/https://www.debian.org/security/2020/dsa-4730
2020-06-16
Published