Ecosyste.ms advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
An open API service providing security vulnerability metadata for many open source software ecosystems.
Improper neutralization of data URIs may allow XSS in rails-html-sanitizer
rails-html-sanitizer >= 1.0.3, < 1.4.4
is vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0
.
Upgrade to rails-html-sanitizer >= 1.4.4
.
The maintainers have evaluated this as Medium Severity 6.1.
This vulnerability was independently reported by Maciej Piechota (@haqpl) and Mrinmoy Das (@goromlagche).
Permalink: https://github.com/advisories/GHSA-mcvf-2q2m-x72m