From df4563ecaf9b30119f3b42bfe1440a450349ff02 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Mon, 1 Jun 2020 10:45:09 +0200 Subject: Mark CVE-2018-3741/ruby-rails-html-sanitizer as no-dsa --- data/CVE/list.2018 | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/list.2018 b/data/CVE/list.2018 index b7a3a25bd1..18eb81126e 100644 --- a/data/CVE/list.2018 +++ b/data/CVE/list.2018 @@ -46348,6 +46348,7 @@ CVE-2018-3742 REJECTED CVE-2018-3741 (There is a possible XSS vulnerability in all rails-html-sanitizer gem ...) - ruby-rails-html-sanitizer 1.0.4-1 (bug #893994) + [stretch] - ruby-rails-html-sanitizer (Minor issue; can be fixed via point release) NOTE: https://github.com/rails/rails-html-sanitizer/commit/f3ba1a839a35f2ba7f941c15e239a1cb379d56ae CVE-2018-3740 (A specially crafted HTML fragment can cause Sanitize gem for Ruby to a ...) {DSA-4358-1} -- cgit v1.2.3