GHSA-f5ww-cq3m-q3g7

    Dashboard / Vulnerabilities / GHSA-f5ww-cq3m-q3g7

    GHSA-f5ww-cq3m-q3g7

    Published: 6 Jul 2023Last Modified: 16 Feb 2024

    Summary: Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content

    Details: ### Impact Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize `>= 3.0.0, < 6.0.2` when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or more CSS at-rules. This could result in XSS (cross-site scripting) or other undesired behavior when the malicious HTML and CSS are rendered in a browser. ### Patches Sanitize `>= 6.0.2` performs additional escaping of CSS in `style` element content, which fixes this issue. ### Workarounds Users who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow `style` elements, using a Sanitize config that doesn't allow CSS at-rules, or by manually escaping the character sequence `</` as `<\/` in `style` element content. ### Credit This issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you!

    Affected packages

    Package

    Name: sanitize

    Purl: pkg:gem/sanitize

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.0.0
    Fixed -6.0.2

    Affected versions

    3.0.0
    3.0.1
    3.0.2
    3.0.3
    3.0.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-f5ww-cq3m-q3g7 | CVE-DB