PT-2022-16045 · Loofah+5 · Loofah+5
Haqpl
·
Published
2022-12-13
·
Updated
2026-03-13
·
CVE-2022-23515
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Loofah versions 2.1.0 through 2.19.0
Description
The issue concerns a cross-site scripting vulnerability via the image/svg+xml media type in data URIs. This vulnerability affects Loofah, a library for manipulating and transforming HTML/XML documents and fragments built on top of Nokogiri.
Recommendations
For Loofah versions 2.1.0 through 2.19.0, upgrade to version 2.19.1 to resolve the issue. As a temporary workaround, consider restricting the use of the image/svg+xml media type in data URIs until the patch is applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Loofah
Nokogiri
Rocky Linux
Suse