Vulnerability Name:

CVE-2018-8048 (CCN-140514)

Assigned:2018-03-19
Published:2018-03-19
Updated:2019-11-22
Summary:In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
CVSS v3 Severity:6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2018-8048

Source: CCN
Type: oss-sec Mailing List, Mon, 19 Mar 2018 17:08:14 -0400
[CVE-2018-8048] Loofah XSS Vulnerability

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20180319 [CVE-2018-8048] Loofah XSS Vulnerability

Source: XF
Type: UNKNOWN
loofah-cve20188048-xss(140514)

Source: CCN
Type: Loofah GIT Repository
CVE-2018-8048 - Loofah XSS Vulnerability #144

Source: CONFIRM
Type: Third Party Advisory
https://github.com/flavorjones/loofah/issues/144

Source: CONFIRM
Type: UNKNOWN
https://security.netapp.com/advisory/ntap-20191122-0003/

Source: DEBIAN
Type: Third Party Advisory
DSA-4171

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-8048

Vulnerable Configuration:Configuration 1:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:loofah_project:loofah:*:*:*:*:*:ruby:*:* (Version < 2.2.1)

  • Configuration CCN 1:
  • cpe:/a:loofah_project:loofah:2.2.0:*:*:*:*:ruby:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20188048
    V
    CVE-2018-8048
    2023-06-22
    oval:org.opensuse.security:def:7799
    P
    ruby2.5-rubygem-nokogiri-1.8.5-150400.14.3.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3193
    P
    libjavascriptcoregtk-4_0-18-2.24.4-2.47.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94823
    P
    ruby2.5-rubygem-nokogiri-1.8.5-150400.12.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:9
    P
    augeas-1.10.1-1.11 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:303
    P
    ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:23
    P
    cairo-devel-1.16.0-1.55 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:357
    P
    ruby2.5-rubygem-nokogiri-1.8.5-150400.12.4 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:1232
    P
    Security update for the Linux Kernel (Important)
    2022-01-19
    oval:org.opensuse.security:def:113394
    P
    ruby2.7-rubygem-nokogiri-1.12.3-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:113391
    P
    ruby2.7-rubygem-loofah-2.12.0-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106800
    P
    Security update for net-snmp (Important)
    2022-01-11
    oval:org.opensuse.security:def:58112
    P
    Security update for libvirt (Important)
    2022-01-10
    oval:org.opensuse.security:def:58074
    P
    Security update for xorg-x11-server (Important)
    2021-12-20
    oval:org.opensuse.security:def:60422
    P
    Security update for ruby2.1 (Important)
    2021-12-01
    oval:org.opensuse.security:def:58054
    P
    Security update for clamav (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:59815
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:67546
    P
    Security update for the Linux Kernel (Important)
    2021-10-15
    oval:org.opensuse.security:def:106797
    P
    ruby2.7-rubygem-loofah-2.12.0-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:58016
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:61676
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63242
    P
    subversion-server-1.10.0-3.3.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61677
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:58000
    P
    Security update for bind (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:57070
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:63377
    P
    squid-4.13-5.23.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63430
    P
    libgstaudio-1_0-0-32bit-1.16.2-2.12 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63480
    P
    libOSMesa8-32bit-20.2.4-57.13 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63338
    P
    libecpg6-13.2-5.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63514
    P
    python2-opencv-3.3.1-6.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:72062
    P
    ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62341
    P
    ucode-intel-20210216-2.19.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62321
    P
    ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63008
    P
    glibc-devel-32bit-2.31-7.20 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101079
    P
    ruby2.5-rubygem-nokogiri-1.8.5-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62145
    P
    libcroco-0.6.13-1.26 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:70786
    P
    Security update for gupnp (Important)
    2021-06-24
    oval:org.opensuse.security:def:57942
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:57457
    P
    Security update for qemu (Important)
    2021-06-08
    oval:org.opensuse.security:def:70899
    P
    expat-2.2.5-1.140 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:57012
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:57908
    P
    Security update for tomcat (Important)
    2021-04-29
    oval:org.opensuse.security:def:59870
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:57185
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:60477
    P
    Security update for apache2 (Moderate)
    2021-03-12
    oval:org.opensuse.security:def:58085
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:57515
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:61700
    P
    automake-1.15.1-2.145 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62687
    P
    libnma-devel-1.8.24-5.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:96508
    P
    ruby2.5-rubygem-loofah-2.2.2-4.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103198
    P
    ruby2.5-rubygem-loofah-2.2.2-4.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61871
    P
    libpython2_7-1_0-2.7.17-7.38.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89543
    P
    ruby2.5-rubygem-loofah-2.2.2-4.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62473
    P
    libtasn1-6-32bit-4.13-2.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63139
    P
    apache2-2.4.33-1.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:56634
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60800
    P
    Security update for postgresql96 (Important)
    2020-12-01
    oval:org.opensuse.security:def:59253
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60850
    P
    Security update for couchdb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60692
    P
    Security update for git (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:59199
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64112
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:56611
    P
    Security update for texlive (Important)
    2020-12-01
    oval:org.opensuse.security:def:59933
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:60721
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:59434
    P
    Security update for postgresql10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60879
    P
    Security update for rubygem-loofah (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56692
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:60855
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60905
    P
    Security update for libpcap (Important)
    2020-12-01
    oval:org.opensuse.security:def:59632
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:56774
    P
    Security update for bash (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60540
    P
    shim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64199
    P
    ruby2.5-rubygem-loofah on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:59254
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:57742
    P
    hplip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56669
    P
    Security update for ghostscript (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:59988
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:58135
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:57243
    P
    Security update for libproxy
    2020-12-01
    oval:org.opensuse.security:def:60776
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:60934
    P
    Security update for rubygem-loofah (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:59221
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:56612
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:60122
    P
    Security update for python-ipaddress (Important)
    2020-12-01
    oval:org.opensuse.security:def:57291
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:60759
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:59687
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:56832
    P
    Security update for doxygen (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60595
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:58159
    P
    Security update for rubygem-loofah (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57800
    P
    libgssglue1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:58143
    P
    Security update for polkit (Important)
    2020-12-01
    oval:org.opensuse.security:def:59198
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:58193
    P
    Security update for rubygem-haml (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60637
    P
    Security update for dovecot22 (Important)
    2020-12-01
    oval:org.opensuse.security:def:59276
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:57850
    P
    libsnmp30-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67446
    P
    Security update for SUSE Manager Server 4.1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56670
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60177
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:57349
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:60814
    P
    Security update for ppp (Important)
    2020-12-01
    oval:org.opensuse.security:def:59379
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:58217
    P
    Security update for rubygem-loofah (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:88285
    P
    Security update for rubygem-loofah (Moderate)
    2019-08-23
    oval:org.opensuse.security:def:84332
    P
    Security update for rubygem-loofah (Moderate)
    2019-08-23
    oval:org.opensuse.security:def:80794
    P
    Security update for rubygem-loofah (Moderate)
    2019-08-23
    oval:org.opensuse.security:def:80852
    P
    Security update for rubygem-loofah (Moderate)
    2019-02-14
    oval:org.opensuse.security:def:84387
    P
    Security update for rubygem-loofah (Moderate)
    2019-02-14
    oval:com.ubuntu.xenial:def:201880480000000
    V
    CVE-2018-8048 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-03-27
    oval:com.ubuntu.artful:def:20188048000
    V
    CVE-2018-8048 on Ubuntu 17.10 (artful) - untriaged.
    2018-03-27
    oval:com.ubuntu.disco:def:201880480000000
    V
    CVE-2018-8048 on Ubuntu 19.04 (disco) - medium.
    2018-03-27
    oval:com.ubuntu.bionic:def:20188048000
    V
    CVE-2018-8048 on Ubuntu 18.04 LTS (bionic) - untriaged.
    2018-03-27
    oval:com.ubuntu.cosmic:def:201880480000000
    V
    CVE-2018-8048 on Ubuntu 18.10 (cosmic) - untriaged.
    2018-03-27
    oval:com.ubuntu.cosmic:def:20188048000
    V
    CVE-2018-8048 on Ubuntu 18.10 (cosmic) - untriaged.
    2018-03-27
    oval:com.ubuntu.bionic:def:201880480000000
    V
    CVE-2018-8048 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-03-27
    oval:com.ubuntu.xenial:def:20188048000
    V
    CVE-2018-8048 on Ubuntu 16.04 LTS (xenial) - untriaged.
    2018-03-27
    BACK
    debian debian linux 9.0
    loofah_project loofah *
    loofah_project loofah 2.2.0