Rails Rails-Html-Sanitizer vulnerabilities

14 known vulnerabilities affecting rails/rails-html-sanitizer.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM8LOW5

Vulnerabilities

Page 1 of 1
CVE-2024-53987LOWCVSS 2.3v>= 1.6.0, < 1.6.12024-12-02
CVE-2024-53987 [LOW] CWE-79 CVE-2024-53987: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 saniti
ghsanvdosv
CVE-2024-53988LOWCVSS 2.3v>= 1.6.0, < 1.6.12024-12-02
CVE-2024-53988 [LOW] CWE-79 CVE-2024-53988: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 saniti
ghsanvdosv
CVE-2024-53986LOWCVSS 2.3v>= 1.6.0, < 1.6.12024-12-02
CVE-2024-53986 [LOW] CWE-79 CVE-2024-53986: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 saniti
ghsanvdosv
CVE-2024-53989LOWCVSS 2.3v>= 1.6.0, < 1.6.12024-12-02
CVE-2024-53989 [LOW] CWE-79 CVE-2024-53989: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 saniti
ghsanvdosv
CVE-2024-53985LOWCVSS 2.3v>= 1.6.0, < 1.6.12024-12-02
CVE-2024-53985 [LOW] CWE-79 CVE-2024-53985: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacke
ghsanvdosv
CVE-2022-23517HIGHCVSS 7.5fixed in 1.4.42022-12-14
CVE-2022-23517 [HIGH] CWE-1333 CVE-2022-23517: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain con rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. T
ghsanvdosv
CVE-2022-23520MEDIUMCVSS 6.1fixed in 1.4.42022-12-14
CVE-2022-23520 [MEDIUM] CWE-79 CVE-2022-23520: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to ve rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overrid
ghsanvdosv
CVE-2022-23518MEDIUMCVSS 6.1v>= 1.0.3, < 1.4.42022-12-14
CVE-2022-23518 [MEDIUM] CWE-79 CVE-2022-23518: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, = 2.1.0. This issue is patched in version 1.4.4.
ghsanvdosv
CVE-2022-23519MEDIUMCVSS 6.1fixed in 1.4.42022-12-14
CVE-2022-23519 [MEDIUM] CWE-79 CVE-2022-23519: rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to ve rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either of the following ways: allow both
ghsanvdosv
CVE-2022-32209MEDIUM≥ 0, < 1.4.32022-06-25
CVE-2022-32209 [MEDIUM] CWE-79 Rails::Html::Sanitizer vulnerable to Cross-site Scripting Rails::Html::Sanitizer vulnerable to Cross-site Scripting Versions of Rails::Html::Sanitizer prior to version 1.4.3 are vulnerable to XSS with certain configurations of Rails::Html::Sanitizer which allows an attacker to inject content when the application developer has overridden the sanitizer's allowed tags to allow both `select` and `style` elements. Code is only impacted if allowed tags are being overrid
ghsaosv
CVE-2018-3741MEDIUMCVSS 6.1≤ 1.0.32018-03-30
CVE-2018-3741 [MEDIUM] CWE-79 CVE-2018-3741: There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All us
ghsanvdosv
CVE-2015-7580MEDIUM≥ 0, < 1.0.32017-10-24
CVE-2015-7580 [MEDIUM] CWE-79 rails-html-sanitizer Cross-site Scripting vulnerability rails-html-sanitizer Cross-site Scripting vulnerability Cross-site scripting (XSS) vulnerability in `lib/rails/html/scrubbers.rb` in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.
ghsaosv
CVE-2015-7579MEDIUM≥ 0, < 1.0.32017-10-24
CVE-2015-7579 [MEDIUM] CWE-79 rails-html-sanitizer Cross-site Scripting vulnerability rails-html-sanitizer Cross-site Scripting vulnerability Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the `Rails::Html::FullSanitizer` class.
ghsaosv
CVE-2015-7578MEDIUM≥ 0, < 1.0.32017-10-24
CVE-2015-7578 [MEDIUM] CWE-79 rails-html-sanitizer Cross-site Scripting vulnerability rails-html-sanitizer Cross-site Scripting vulnerability Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes.
ghsaosv