UbuntuUpdates.org

Package "ruby-sanitize"

Name: ruby-sanitize

Description:

whitelist-based HTML sanitizer

Latest version: 6.0.0-1.1ubuntu0.23.10.1
Release: mantic (23.10)
Level: security
Repository: universe
Homepage: https://github.com/rgrove/sanitize/

Links


Download "ruby-sanitize"


Other versions of "ruby-sanitize" in Mantic

Repository Area Version
base universe 6.0.0-1.1
updates universe 6.0.0-1.1ubuntu0.23.10.1

Changelog

Version: 6.0.0-1.1ubuntu0.23.10.1 2024-04-24 07:06:58 UTC

  ruby-sanitize (6.0.0-1.1ubuntu0.23.10.1) mantic-security; urgency=medium

  * SECURITY UPDATE: XSS via style element when using "relaxed" or custom
    config
    - debian/patches/CVE-2023-36823.patch: prevent style element from
      premature close by escaping "</" in
      lib/sanitize/transformers/clean_css.rb.
    - CVE-2023-36823

 -- Evan Caville <email address hidden> Fri, 19 Apr 2024 12:30:54 +1000

CVE-2023-36823 Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through



About   -   Send Feedback to @ubuntu_updates