Vulnerabilities
Vulnerable Software
Loofah Project:  >> Loofah  >> 2.0.2  Security Vulnerabilities
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-12-14
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVSS Score
5.4
EPSS Score
0.017
Published
2019-10-22
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVSS Score
5.4
EPSS Score
0.003
Published
2018-10-30
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
CVSS Score
6.1
EPSS Score
0.004
Published
2018-03-27


Contact Us

Shodan ® - All rights reserved