CVE-2019-15587
22.10.2019, 21:15
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
| Vendor | Product | Version |
|---|---|---|
| loofah_project | loofah | 𝑥 ≤ 2.3.0 |
| canonical | ubuntu_linux | 16.04 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References