ReDoS (Rails::Html::PermitScrubber.scrub_attribute)

Disclosed: 2022-12-14 22:51:27 By ooooooo_q To ibb
High
Vulnerability Details
I reported at https://hackerone.com/reports/1684163 https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-5x79-w82f-gw8w > Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. It seems that the same problem existed on the Loofah side, so it was fixed as well. That has been fixed as CVE-2022-23514(https://github.com/flavorjones/loofah/security/advisories/GHSA-486f-hjj9-9vhh) ## Impact ReDoS may occur if scrub is executed in Rails::Html::PermitScrubber.
Actions
View on HackerOne
Report Stats
  • Report ID: 1804128
  • State: Closed
  • Substate: resolved
  • Upvotes: 15
Share this report