a90d040e-f5b0-11e9-acc4-4576b265fda6Loofah -- XSS vulnerability

GitHub issue:

This issue has been created for public disclosure of an XSS vulnerability that was responsibly reported by

In the Loofah gem, through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

Discovery 2019-10-22
Entry 2019-10-23
lt 2.3.1