Debian Security Update DSA-4171 ruby-loofah - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,810
Reaction score
74
Credits
-1,257
The Shopify Application Security Team reported that ruby-loofah, a general library for manipulating and transforming HTML/XML documents and fragments, allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. This might allow to mount a code injection attack into a browser consuming sanitized output.

Continue reading...
 


Follow Linux.org

Members online


Top