---
cve: "CVE-2019-15587"
severity: "LOW"
cvss: 3.1
epss: "1.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2019-10-22 21:15:10"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T14:36:26+02:00"
---

# CVE-2019-15587

> 3.1 LOW · 🧪 PoC

## Beschreibung

In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

## Referenzen

- <https://hackerone.com/reports/709009>
- <https://github.com/flavorjones/loofah/issues/171>
- <https://www.debian.org/security/2019/dsa-4554>
- <https://security.netapp.com/advisory/ntap-20191122-0003/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WK2UG7ORKRQOJ6E4XJ2NVIHYJES6BYZ/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XMCWPLYPNIWYAY443IZZJ4IHBBLIHBP5/>
- <https://usn.ubuntu.com/4498-1/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-15587) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
