Skip to content

Commit

Permalink
Bump Loofah version to 2.3.1
Browse files Browse the repository at this point in the history
Vulnerability CVE-2019-15587
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur
in sanitized output when a crafted SVG element is republished.

flavorjones/loofah#171
  • Loading branch information
rokumatsumoto committed Oct 24, 2019
1 parent 92fa81c commit 7d35655
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion Gemfile.lock
Expand Up @@ -238,7 +238,7 @@ GEM
rb-inotify (~> 0.9, >= 0.9.7)
ruby_dep (~> 1.2)
local_time (2.1.0)
loofah (2.3.0)
loofah (2.3.1)
crass (~> 1.0.2)
nokogiri (>= 1.5.9)
lumberjack (1.0.13)
Expand Down

0 comments on commit 7d35655

Please sign in to comment.