title: XSS vulnerability in rails-html-sanitizer
There is a possible XSS vulnerability in rails-html-sanitizer. The gem allows
non-whitelisted attributes to be present in sanitized output when input with
specially-crafted HTML fragments, and these attributes can lead to an XSS attack
on target applications.
This issue is similar to CVE-2018-8048 in Loofah.
- ">= 1.0.4"