PT-2019-5086 · Ruby+2 · Loofah+2
Published
2019-10-22
·
Updated
2026-03-13
·
CVE-2019-15587
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Loofah gem for Ruby versions through 2.3.0
Description
The issue is related to the Loofah gem for Ruby, where unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. This could potentially allow a remote attacker to impact data integrity by exploiting the vulnerability, which is associated with a lack of protection for the web page structure.
Recommendations
For Loofah gem for Ruby versions through 2.3.0, consider disabling the use of crafted SVG elements in the sanitization process until a patch is available. Restrict access to the sanitization module to minimize the risk of exploitation. Avoid using the Loofah gem for Ruby for sensitive data processing until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loofah
Suse
Ubuntu