RubySec

Providing security resources for the Ruby community

CVE-2022-23517 (rails-html-sanitizer): Inefficient Regular Expression Complexity in rails-html-sanitizer

ADVISORIES

GEM

rails-html-sanitizer

SEVERITY

CVSS v3.x: 7.5 (High)

PATCHED VERSIONS

  • >= 1.4.4

DESCRIPTION

Summary

Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.

Mitigation

Upgrade to rails-html-sanitizer >= 1.4.4.

RELATED