Candidate: CVE-2018-3740 PublicDate: 2018-03-30 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3740 https://github.com/rgrove/sanitize/issues/176 https://github.com/rgrove/sanitize/commit/01629a162e448a83d901456d0ba8b65f3b03d46e Description: A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=893610 Priority: untriaged Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_ruby-sanitize: upstream_ruby-sanitize: released (4.6.5-1, 4.6.6-1) precise/esm_ruby-sanitize: DNE trusty_ruby-sanitize: DNE trusty/esm_ruby-sanitize: DNE xenial_ruby-sanitize: released (2.1.0-2+deb9u1build0.16.04.1) artful_ruby-sanitize: ignored (reached end-of-life) bionic_ruby-sanitize: released (2.1.0-2+deb9u1build0.18.04.1) cosmic_ruby-sanitize: not-affected (4.6.6-1) devel_ruby-sanitize: not-affected (4.6.6-1)