{"schema_version":"1.7.3","id":"GHSA-x7rv-cr6v-4vm4","published":"2018-03-21T11:57:11Z","modified":"2024-02-22T05:21:17.045269Z","aliases":["CVE-2018-8048"],"summary":"Cross-site Scripting in loofah","details":"Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments.\n\nUsers are affected if running Loofah < 2.2.1, but only:\n\n* when running on MRI or RBX,\n* in combination with libxml2 >= 2.9.2.\n\nJRuby users are not affected.","affected":[{"package":{"name":"loofah","ecosystem":"RubyGems","purl":"pkg:gem/loofah"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.1"}]}],"versions":["0.2.0","0.2.1","0.2.2","0.3.0","0.3.1","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","1.0.0","1.0.0.beta.1","1.1.0","1.2.0","1.2.1","2.0.0","2.0.1","2.0.2","2.0.3","2.1.0","2.1.0.rc1","2.1.0.rc2","2.1.1","2.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/03/GHSA-x7rv-cr6v-4vm4/GHSA-x7rv-cr6v-4vm4.json"}},{"package":{"name":"nokogiri","ecosystem":"RubyGems","purl":"pkg:gem/nokogiri"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.3"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.3.1","1.3.2","1.3.3","1.4.0","1.4.1","1.4.2","1.4.2.1","1.4.3","1.4.3.1","1.4.4","1.4.4.1","1.4.4.2","1.4.5","1.4.6","1.4.7","1.5.0","1.5.0.beta.1","1.5.0.beta.2","1.5.0.beta.3","1.5.0.beta.4","1.5.1","1.5.1.rc1","1.5.10","1.5.11","1.5.2","1.5.3","1.5.3.rc2","1.5.3.rc3","1.5.3.rc4","1.5.3.rc5","1.5.3.rc6","1.5.4","1.5.4.rc1","1.5.4.rc2","1.5.4.rc3","1.5.5","1.5.5.rc1","1.5.5.rc2","1.5.5.rc3","1.5.6","1.5.6.rc1","1.5.6.rc2","1.5.6.rc3","1.5.7","1.5.7.rc1","1.5.7.rc2","1.5.7.rc3","1.5.8","1.5.9","1.6.0","1.6.0.rc1","1.6.1","1.6.2","1.6.2.1","1.6.2.rc1","1.6.2.rc2","1.6.2.rc3","1.6.3","1.6.3.1","1.6.3.rc1","1.6.3.rc2","1.6.3.rc3","1.6.4","1.6.4.1","1.6.5","1.6.6.1","1.6.6.2","1.6.6.3","1.6.6.4","1.6.7","1.6.7.1","1.6.7.2","1.6.7.rc2","1.6.7.rc3","1.6.7.rc4","1.6.8","1.6.8.1","1.6.8.rc1","1.6.8.rc2","1.6.8.rc3","1.7.0","1.7.0.1","1.7.1","1.7.2","1.8.0","1.8.1","1.8.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/03/GHSA-x7rv-cr6v-4vm4/GHSA-x7rv-cr6v-4vm4.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-8048"},{"type":"WEB","url":"https://github.com/flavorjones/loofah/issues/144"},{"type":"WEB","url":"https://github.com/sparklemotion/nokogiri/pull/1746"},{"type":"WEB","url":"https://github.com/flavorjones/loofah/commit/f739cf8eac5851f328b8044281d6653f74eff116"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-x7rv-cr6v-4vm4"},{"type":"WEB","url":"https://github.com/flavorjones/loofah"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/loofah/CVE-2018-8048.yml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2018-8048.yml"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20191122-0003"},{"type":"WEB","url":"https://www.debian.org/security/2018/dsa-4171"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2018/03/19/5"}],"database_specific":{"cwe_ids":["CWE-79"],"github_reviewed":true,"github_reviewed_at":"2020-06-16T22:02:35Z","nvd_published_at":null,"severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}