CVE-2022-23519
Description
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either of the following ways: allow both 'math' and 'style' elements, or allow both 'svg' and 'style' elements. Code is only impacted if allowed tags are being overridden. . This issue is fixed in version 1.4.4. All users overriding the allowed tags to include 'math' or 'svg' and 'style' should either upgrade or use the following workaround immediately: Remove 'style' from the overridden allowed tags, or remove 'math' and 'svg' from the overridden allowed tags.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
StableCommon Consequences
Applicable Platforms
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Rails Html Sanitizers by Rubyonrails
cpe:2.3:a:rubyonrails:rails_html_sanitizers:*:*:*:*:*:rails:*:*