VYPR

rpm package

opensuse/ruby3.2-rubygem-loofah&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ruby3.2-rubygem-loofah&distro=openSUSE%20Tumbleweed

Vulnerabilities (3)

  • CVE-2019-15587Oct 22, 2019
    affected < 2.19.1-1.2fixed 2.19.1-1.2

    In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

  • CVE-2018-16468Oct 30, 2018
    affected < 2.19.1-1.2fixed 2.19.1-1.2

    In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

  • CVE-2018-8048Mar 27, 2018
    affected < 2.19.1-1.2fixed 2.19.1-1.2

    In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.