Medium severity5.4NVD Advisory· Published Oct 22, 2019· Updated Jun 17, 2026
CVE-2019-15587
CVE-2019-15587
Description
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
loofahRubyGems | < 2.3.1 | 2.3.1 |
Affected products
19- Ruby/Loofah gemdescription
- ghsa-coords12 versionspkg:gem/loofahpkg:rpm/opensuse/rubygem-loofah&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ruby3.2-rubygem-loofah&distro=openSUSE%20Tumbleweedpkg:rpm/suse/rubygem-loofah&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/rubygem-loofah&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1pkg:rpm/suse/rubygem-loofah&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP2pkg:rpm/suse/rubygem-loofah&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP3pkg:rpm/suse/rubygem-loofah&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP4pkg:rpm/opensuse/rubygem-loofah&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/rubygem-loofah&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/rubygem-loofah&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/opensuse/rubygem-loofah&distro=openSUSE%20Leap%2015.4
< 2.3.1+ 11 more
- (no CPE)range: < 2.3.1
- (no CPE)range: < 2.14.0-1.1
- (no CPE)range: < 2.19.1-1.2
- (no CPE)range: < 2.2.2-150000.4.6.1
- (no CPE)range: < 2.2.2-150000.4.6.1
- (no CPE)range: < 2.2.2-150000.4.6.1
- (no CPE)range: < 2.2.2-150000.4.6.1
- (no CPE)range: < 2.2.2-150000.4.6.1
- (no CPE)range: < 2.2.2-150000.4.6.1
- (no CPE)range: < 2.0.2-3.11.1
- (no CPE)range: < 2.0.2-3.11.1
- (no CPE)range: < 2.2.2-150000.4.6.1
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
Patches
Vulnerability mechanics
References
15- github.com/advisories/GHSA-c3gv-9cxf-6f57ghsaADVISORY
- github.com/flavorjones/loofah/issues/171nvdThird Party AdvisoryWEB
- hackerone.com/reports/709009nvdPermissions RequiredThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-15587ghsaADVISORY
- security.netapp.com/advisory/ntap-20191122-0003/nvdThird Party Advisory
- usn.ubuntu.com/4498-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4554nvdThird Party AdvisoryWEB
- github.com/flavorjones/loofah/commit/0c6617af440879ce97440f6eb6c58636456dc8ecghsaWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/loofah/CVE-2019-15587.ymlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/4WK2UG7ORKRQOJ6E4XJ2NVIHYJES6BYZghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/XMCWPLYPNIWYAY443IZZJ4IHBBLIHBP5ghsaWEB
- security.netapp.com/advisory/ntap-20191122-0003ghsaWEB
- usn.ubuntu.com/4498-1ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WK2UG7ORKRQOJ6E4XJ2NVIHYJES6BYZ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XMCWPLYPNIWYAY443IZZJ4IHBBLIHBP5/nvd
News mentions
0No linked articles in our index yet.