GHSA-pg8v-g4xq-hww9
Dashboard / Vulnerabilities / GHSA-pg8v-g4xq-hww9
Summary: Rails::Html::Sanitizer vulnerable to Cross-site Scripting
Details: Versions of Rails::Html::Sanitizer prior to version 1.4.3 are vulnerable to XSS with certain configurations of Rails::Html::Sanitizer which allows an attacker to inject content when the application developer has overridden the sanitizer's allowed tags to allow both `select` and `style` elements. Code is only impacted if allowed tags are being overridden. This may be done via application configuration: ```ruby# In config/application.rbconfig.action_view.sanitized_allowed_tags = ["select", "style"]``` see https://guides.rubyonrails.org/configuring.html#configuring-action-view Or it may be done with a `:tags` option to the Action View helper `sanitize`: ```<%= sanitize @comment.body, tags: ["select", "style"] %>``` see https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-sanitize It may also be done with Rails::Html::SafeListSanitizer directly: ```ruby# class-level optionRails::Html::SafeListSanitizer.allowed_tags = ["select", "style"]``` or with ```ruby# instance-level optionRails::Html::SafeListSanitizer.new.sanitize(@article.body, tags: ["select", "style"])``` All users overriding the allowed tags by any of the above mechanisms to include both "select" and "style" are recommended to upgrade immediately. A workaround for this issue can be applied by removing either `select` or `style` from the overridden allowed tags.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-32209, https://github.com/rails/rails-html-sanitizer/commit/45a5c10fed3d9aa141594c80afa06d748fa0967d, https://hackerone.com/reports/1530898, https://github.com/rails/rails-html-sanitizer, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rails-html-sanitizer/CVE-2022-32209.yml, https://groups.google.com/g/rubyonrails-security/c/ce9PhUANQ6s, https://lists.debian.org/debian-lts-announce/2022/12/msg00012.html, https://lists.debian.org/debian-lts-announce/2024/09/msg00045.html, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGRLWBEB3S5AU3D4TTROIS7O6QPHDTRH, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NHDACMCLWE32BZZTSNWQPIFUAD5I6Q47, https://lists.fedoraproject.org/archives/list/[email protected]/message/AGRLWBEB3S5AU3D4TTROIS7O6QPHDTRH, https://lists.fedoraproject.org/archives/list/[email protected]/message/NHDACMCLWE32BZZTSNWQPIFUAD5I6Q47
Affected packages
Package
Name: rails-html-sanitizer
Purl: pkg:gem/rails-html-sanitizer
Affected ranges
Type: ECOSYSTEM
Events:
