GHSA-cj75-f6xr-r4g7: Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as <use>. See related GHSA-9wjq-cp2p-hrgf in Loofah, whose SVG local-reference logic rails-html-sanitizer mirrors.
- Versions affected:
>= 1.0.3, < 1.7.1 - Not affected:
< 1.0.3 - Fixed versions:
1.7.1
References
Code Behaviors & Features
Detect and mitigate GHSA-cj75-f6xr-r4g7 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →