Rubyonrails Html Sanitizer vulnerabilities

4 known vulnerabilities affecting rubyonrails/html_sanitizer.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2018-3741MEDIUMCVSS 6.1≤ 1.0.32018-03-30
CVE-2018-3741 [MEDIUM] CWE-79 CVE-2018-3741: There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All us
nvd
CVE-2015-7579MEDIUMCVSS 6.1≤ 1.0.22016-02-16
CVE-2015-7579 [MEDIUM] CWE-79 CVE-2015-7579: Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2 Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class.
nvd
CVE-2015-7580MEDIUMCVSS 6.1≤ 1.0.22016-02-16
CVE-2015-7580 [MEDIUM] CWE-79 CVE-2015-7580: Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.
nvd
CVE-2015-7578MEDIUMCVSS 6.1≤ 1.0.22016-02-16
CVE-2015-7578 [MEDIUM] CWE-79 CVE-2015-7578: Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Ra Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes.
nvd