Vulnerability Bulletins

DSA-4171 ruby-loofah - security update

   
Affected software Debian
 
The Shopify Application Security Team reported that ruby-loofah, ageneral library for manipulating and transforming HTML/XML documents andfragments, allows non-whitelisted attributes to be present in sanitizedoutput when input with specially-crafted HTML fragments. This mightallow to mount a code injection attack into a browser consumingsanitized output.

More info:

https://www.debian.org/security/2018/dsa-4171