Debian Ruby-Rails-Html-Sanitizer vulnerabilities

14 known vulnerabilities affecting debian/ruby-rails-html-sanitizer.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM7LOW5

Vulnerabilities

Page 1 of 1
CVE-2024-53988LOWCVSS 2.32024
CVE-2024-53988 [LOW] CVE-2024-53988: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 s
debian
CVE-2024-53986LOWCVSS 2.32024
CVE-2024-53986 [LOW] CVE-2024-53986: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 s
debian
CVE-2024-53987LOWCVSS 2.32024
CVE-2024-53987 [LOW] CVE-2024-53987: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 s
debian
CVE-2024-53985LOWCVSS 2.32024
CVE-2024-53985 [LOW] CVE-2024-53985: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an at
debian
CVE-2024-53989LOWCVSS 2.32024
CVE-2024-53989 [LOW] CVE-2024-53989: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 s
debian
CVE-2022-23519HIGHCVSS 7.2fixed in ruby-rails-html-sanitizer 1.4.4-1 (bookworm)2022
CVE-2022-23519 [HIGH] CVE-2022-23519: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either of the following ways: allow bo
debian
CVE-2022-23517HIGHCVSS 7.5fixed in ruby-rails-html-sanitizer 1.4.4-1 (bookworm)2022
CVE-2022-23517 [HIGH] CVE-2022-23517: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.
debian
CVE-2022-23520MEDIUMCVSS 6.1fixed in ruby-rails-html-sanitizer 1.4.4-1 (bookworm)2022
CVE-2022-23520 [MEDIUM] CVE-2022-23520: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has ove
debian
CVE-2022-23518MEDIUMCVSS 6.1fixed in ruby-rails-html-sanitizer 1.4.4-1 (bookworm)2022
CVE-2022-23518 [MEDIUM] CVE-2022-23518: ruby-rails-html-sanitizer - rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails appli... rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, = 2.1.0. This issue is patched in version 1.4.4. Scope: local bookworm: resolved (fixed in 1.4.4-1) bullseye: resolved (fixed in 1.3.0-1+deb11u1) forky: resolved (fixed in 1.4.4-1) sid: resolved (fixed in 1.4.4-1) trixie: resolved (fixed in
debian
CVE-2022-32209MEDIUMCVSS 6.1fixed in ruby-rails-html-sanitizer 1.4.3-0.1 (bookworm)2022
CVE-2022-32209 [MEDIUM] CVE-2022-32209: ruby-rails-html-sanitizer - # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vu... # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected: NONEFixed Versions: v1.4.3## ImpactA possible XSS vulnerability with certain configurations of
debian
CVE-2018-3741MEDIUMCVSS 6.1fixed in ruby-rails-html-sanitizer 1.0.4-1 (bookworm)2018
CVE-2018-3741 [MEDIUM] CVE-2018-3741: ruby-rails-html-sanitizer - There is a possible XSS vulnerability in all rails-html-sanitizer gem versions b... There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. Al
debian
CVE-2015-7579MEDIUMCVSS 6.1fixed in ruby-rails-html-sanitizer 1.0.3-1 (bookworm)2015
CVE-2015-7579 [MEDIUM] CVE-2015-7579: ruby-rails-html-sanitizer - Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 f... Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class. Scope: local bookworm: resolved (fixed in 1.0.3-1) bullseye: resolved (fixed in 1.0.3-1) forky: r
debian
CVE-2015-7578MEDIUMCVSS 6.1fixed in ruby-rails-html-sanitizer 1.0.3-1 (bookworm)2015
CVE-2015-7578 [MEDIUM] CVE-2015-7578: ruby-rails-html-sanitizer - Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before ... Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes. Scope: local bookworm: resolved (fixed in 1.0.3-1) bullseye: resolved (fixed in 1.0.3-1) forky: resolved (fixed in 1.0.3-1) sid: resolved (fi
debian
CVE-2015-7580MEDIUMCVSS 6.1fixed in ruby-rails-html-sanitizer 1.0.3-1 (bookworm)2015
CVE-2015-7580 [MEDIUM] CVE-2015-7580: ruby-rails-html-sanitizer - Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the r... Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node. Scope: local bookworm: resolved (fixed in 1.0.3-1) bullseye: resolved (fixed in 1.0.3-1) forky: resolved (fixed
debian