CVE-2018-8048: Debian Linux
Medium severity, CVSS 6.1. EPSS: 1.9% chance of exploitation in the next 30 days.
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
Affected products
- Debian Debian Linux: version 9.0 only
- Loofah Project Loofah: before 2.2.1 (fixed in 2.2.1)
Published 2018-03-27. Last modified 2026-06-17.