FreeBSD : Loofah -- XSS vulnerability (ba6d0c9b-f5f6-4b9b-a6de-3cce93c83220)

medium Nessus Plugin ID 108508

Language:

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

GitHub issue :

This issue has been created for public disclosure of an XSS / code injection vulnerability that was responsibly reported by the Shopify Application Security Team.

Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially crafted HTML fragments.

Solution

Update the affected package.

See Also

https://github.com/flavorjones/loofah/releases

https://github.com/flavorjones/loofah/issues/144

http://www.nessus.org/u?4776bd17

Plugin Details

Severity: Medium

ID: 108508

File Name: freebsd_pkg_ba6d0c9bf5f64b9ba6de3cce93c83220.nasl

Version: 1.4

Type: local

Published: 3/21/2018

Updated: 11/10/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:rubygem-loofah, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 3/20/2018

Vulnerability Publication Date: 3/15/2018

Reference Information

CVE: CVE-2018-8048