PT-2019-5086 · Ruby+2 · Loofah+2

Published

2019-10-22

·

Updated

2026-03-13

·

CVE-2019-15587

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Loofah gem for Ruby versions through 2.3.0
Description The issue is related to the Loofah gem for Ruby, where unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. This could potentially allow a remote attacker to impact data integrity by exploiting the vulnerability, which is associated with a lack of protection for the web page structure.
Recommendations For Loofah gem for Ruby versions through 2.3.0, consider disabling the use of crafted SVG elements in the sanitization process until a patch is available. Restrict access to the sanitization module to minimize the risk of exploitation. Avoid using the Loofah gem for Ruby for sensitive data processing until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2020-01752
CVE-2019-15587
DSA-4554-1
GHSA-C3GV-9CXF-6F57
OPENSUSE-SU-2022_3868-1
OPENSUSE-SU-2024:11337-1
OPENSUSE-SU-2024:11900-1
OPENSUSE-SU-2024:13162-1
OPENSUSE-SU-2024:14171-1
OPENSUSE-SU-2025:15120-1
OPENSUSE-SU-2026:10353-1
SUSE-SU-2022:3868-1
SUSE-SU-2022:4075-1
SUSE-SU-2022_3868-1
USN-4498-1

Affected Products

Loofah
Suse
Ubuntu