CVE Database
/

CVE-2018-16468

Back to search

CVE-2018-16468

Published: Oct 30, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

VendorProductVersions

n/a

Loofah (Ruby Gem)

affected
v2.2.3

Weaknesses (CWE)

References

DSA-4364
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now