diff --git a/gems/loofah/CVE-2019-15587.yml b/gems/loofah/CVE-2019-15587.yml new file mode 100644 index 0000000000..e0226ad786 --- /dev/null +++ b/gems/loofah/CVE-2019-15587.yml @@ -0,0 +1,13 @@ +--- +gem: loofah +cve: 2019-15587 +url: https://github.com/flavorjones/loofah/issues/171 +title: Loofah XSS Vulnerability +date: 2019-10-22 +description: | + In the Loofah gem, through v2.3.0, unsanitized JavaScript may occur in + sanitized output when a crafted SVG element is republished. + +cvss_v3: 6.4 +patched_versions: + - ">= 2.3.1"