PT-2022-7455 · Rubygems+5 · Rails-Html-Sanitizer+5
Ooooooo_Q
·
Published
2022-12-13
·
Updated
2026-03-13
·
CVE-2022-23517
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
rails-html-sanitizer versions < 1.4.4
Description
The issue is related to certain configurations of rails-html-sanitizer that use an inefficient regular expression. This inefficiency can lead to excessive backtracking when attempting to sanitize certain SVG attributes, resulting in a denial of service through CPU resource consumption. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations
Upgrade to rails-html-sanitizer version 1.4.4 or later.
Exploit
Fix
RCE
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Red Os
Rocky Linux
Suse
Rails-Html-Sanitizer