Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2022-23516

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack...

1 affected packages

ruby-loofah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-loofah Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-23515

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data...

1 affected packages

ruby-loofah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-loofah Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-23514

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking...

1 affected packages

ruby-loofah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-loofah Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2019-15587

Medium priority

Some fixes available 1 of 4

In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

1 affected packages

ruby-loofah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-loofah Not affected Not affected Not affected Needs evaluation Fixed
Show less packages

CVE-2018-16468

Low priority

Some fixes available 1 of 3

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

1 affected packages

ruby-loofah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-loofah Not affected Not affected Not affected Vulnerable Fixed
Show less packages

CVE-2018-8048

Medium priority
Ignored

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

1 affected packages

ruby-loofah

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ruby-loofah Not affected Not affected
Show less packages