Ubuntu CVE Tracker
Home
Main
Universe
Partner
CVE-2018-3740
Priority
Untriaged
Description
A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow
non-whitelisted attributes to be used on a whitelisted HTML element.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3740
https://github.com/rgrove/sanitize/issues/176
https://github.com/rgrove/sanitize/commit/01629a162e448a83d901456d0ba8b65f3b03d46e
Bugs
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=893610
Notes
Package
Source:
ruby-sanitize
(
LP
Ubuntu
Debian
)
Upstream:
released
(4.6.5-1, 4.6.6-1)
Ubuntu 18.04 LTS
:
released
(2.1.0-2+deb9u1build0.18.04.1)
Ubuntu 14.04 ESM:
DNE
Patches:
More Information
Mitre
NVD
Launchpad
Debian
Updated
: 2022-04-13 13:32:28 UTC (commit
f411bd370d482ef4385c4e751d121a4055fbc009
)