rubygem-loofah: XXS when a crafted SVG element is republished
Published Oct 22, 2019
5.4
MEDIUMCVSS 3.1
EPSS 1.56%
Description
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Affected products
- Vendor n/a Product Loofah (rubygem) Defaultn/a
- Version Fixed in v2.3.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Loofah (rubygem) | n/a |
|
Configuration 1
- ≤ 2.3.0
Configuration 2
- 30
- 31
Configuration 3
- 16.04
Configuration 4
- 9.0
- 10.0
No data.
CloudForms Management Engine 5
cfme-amazon-smartstate
Will not fix
CloudForms Management Engine 5
cfme-gemset
Will not fix
Red Hat Satellite 6
tfm-ror51-rubygem-loofah
Not affected
Red Hat Satellite 6
tfm-ror52-rubygem-loofah
Not affected
Red Hat Software Collections
rh-ror50-rubygem-loofah
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | cfme-amazon-smartstate | Will not fix | n/a |
| CloudForms Management Engine 5 | cfme-gemset | Will not fix | n/a |
| Red Hat Satellite 6 | tfm-ror51-rubygem-loofah | Not affected | n/a |
| Red Hat Satellite 6 | tfm-ror52-rubygem-loofah | Not affected | n/a |
| Red Hat Software Collections | rh-ror50-rubygem-loofah | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Supported versions of Satellite 6 contain a vulnerable version of rubygem-loofah. However, it is not possible to inject untrusted SVG files, and thus it is considered that this vulnerability can not be triggered. A future update may fix this vulnerability.
References (17)
- https://access.redhat.com/security/cve/CVE-2019-15587 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1774081 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0741 Advisory
- https://github.com/advisories/GHSA-c3gv-9cxf-6f57 Advisory
- https://github.com/flavorjones/loofah/commit/0c6617af440879ce97440f6eb6c58636456dc8ec
- https://github.com/flavorjones/loofah/issues/171 x_refsource_CONFIRMThird Party Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/loofah/CVE-2019-15587.yml
- https://hackerone.com/reports/709009 x_refsource_MISCPermissions RequiredThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WK2UG7ORKRQOJ6E4XJ2NVIHYJES6BYZ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XMCWPLYPNIWYAY443IZZJ4IHBBLIHBP5/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4WK2UG7ORKRQOJ6E4XJ2NVIHYJES6BYZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XMCWPLYPNIWYAY443IZZJ4IHBBLIHBP5/
- https://nvd.nist.gov/vuln/detail/CVE-2019-15587
- https://security.netapp.com/advisory/ntap-20191122-0003/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4498-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-15587
- https://www.debian.org/security/2019/dsa-4554 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.