[ubuntu/jammy-security] ruby-sanitize 6.0.0-1ubuntu0.1 (Accepted)

Evan Caville evan.caville at canonical.com
Wed Apr 24 05:57:53 UTC 2024


ruby-sanitize (6.0.0-1ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: XSS via noscript elements when using custom allowlist
    - debian/patches/CVE-2023-23627.patch: always remove noscript elements, 
      even if they're included in the allowlist in
      lib/sanitize/transformers/clean_element.rb.
    - CVE-2023-23627  
  * SECURITY UPDATE: XSS via style element when using "relaxed" or custom 
    config
    - debian/patches/CVE-2023-36823.patch: prevent style element from
      premature close by escaping "</" in 
      lib/sanitize/transformers/clean_css.rb.
    - CVE-2023-36823

Date: 2024-04-19 07:55:09.998259+00:00
Changed-By: Evan Caville <evan.caville at canonical.com>
https://launchpad.net/ubuntu/+source/ruby-sanitize/6.0.0-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list