Debian Security Update DSA-4730 ruby-sanitize - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
30
Reaction score
10
Credits
0
Michal Bentkowski discovered that ruby-sanitize, a whitelist-based HTML sanitizer, is prone to a HTML sanitization bypass vulnerability when using the relaxed or a custom config allowing certain elements. Content in a or element may not be sanitized correctly even if math and svg are not in the allowlist.

Continue reading...
 

Members online


Top