Vulnerability Bulletins |
DSA-4171 ruby-loofah - security update |
|
| Affected software | Debian |
|
The Shopify Application Security Team reported that ruby-loofah, ageneral library for manipulating and transforming HTML/XML documents andfragments, allows non-whitelisted attributes to be present in sanitizedoutput when input with specially-crafted HTML fragments. This mightallow to mount a code injection attack into a browser consumingsanitized output. More info: https://www.debian.org/security/2018/dsa-4171 |
|






