{"id":"GHSA-242p-4v39-2v8g","summary":"Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex","details":"There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent these attacks.\n\n### Impact\n\nIf you render an `\u003ca\u003e` tag with an `href` attribute set to a user-provided link, that link could potentially execute JavaScript when clicked by another user.\n\n```ruby\na(href: user_profile) { \"Profile\" }\n```\n\nIf you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.\n\n```ruby\nh1(**JSON.parse(user_attributes))\n```\n\n### Patches\nPatches are [available on RubyGems](https://rubygems.org/gems/phlex) for all `1.x` minor versions. The patched versions are:\n\n- [1.9.1](https://rubygems.org/gems/phlex/versions/1.9.1)\n- [1.8.2](https://rubygems.org/gems/phlex/versions/1.8.2)\n- [1.7.1](https://rubygems.org/gems/phlex/versions/1.7.1)\n- [1.6.2](https://rubygems.org/gems/phlex/versions/1.6.2)\n- [1.5.2](https://rubygems.org/gems/phlex/versions/1.5.2)\n- [1.4.1](https://rubygems.org/gems/phlex/versions/1.4.1)\n- [1.3.3](https://rubygems.org/gems/phlex/versions/1.3.3)\n- [1.2.2](https://rubygems.org/gems/phlex/versions/1.2.2)\n- [1.1.1](https://rubygems.org/gems/phlex/versions/1.1.1)\n- [1.0.1](https://rubygems.org/gems/phlex/versions/1.0.1)\n\nIf you are on `main`, it has been patched since [`aa50c60`](https://github.com/phlex-ruby/phlex/commit/aa50c604cdee1d0ce7ef068a4c66cbd5d43f96a1)\n\n### Workarounds\nConfiguring a [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy) that does not allow [`unsafe-inline`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy#unsafe-inline) would effectively prevent this vulnerability from being exploited.\n\n### References\n\nIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow `unsafe-inline`. Here’s how you can configure a Content Security Policy header in Rails. https://guides.rubyonrails.org/security.html#content-security-policy-header","aliases":["CVE-2024-28199"],"modified":"2026-09-10T03:50:00.390202157Z","published":"2024-03-12T15:39:46Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-03-12T15:39:46Z","nvd_published_at":"2024-03-11T23:15:47Z"},"references":[{"type":"WEB","url":"https://github.com/phlex-ruby/phlex/security/advisories/GHSA-242p-4v39-2v8g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28199"},{"type":"WEB","url":"https://github.com/phlex-ruby/phlex/commit/aa50c604cdee1d0ce7ef068a4c66cbd5d43f96a1"},{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy"},{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy#unsafe-inline"},{"type":"PACKAGE","url":"https://github.com/phlex-ruby/phlex"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/phlex/CVE-2024-28199.yml"}],"affected":[{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.9.0"},{"fixed":"1.9.1"}]}],"versions":["1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.8.0"},{"fixed":"1.8.2"}]}],"versions":["1.8.0","1.8.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.0"},{"fixed":"1.7.1"}]}],"versions":["1.7.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.6.0"},{"fixed":"1.6.2"}]}],"versions":["1.6.0","1.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.5.0"},{"fixed":"1.5.2"}]}],"versions":["1.5.0","1.5.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.4.0"},{"fixed":"1.4.1"}]}],"versions":["1.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3.0"},{"fixed":"1.3.3"}]}],"versions":["1.3.0","1.3.1","1.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0"},{"fixed":"1.2.2"}]}],"versions":["1.2.0","1.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0"},{"fixed":"1.1.1"}]}],"versions":["1.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}},{"package":{"name":"phlex","ecosystem":"RubyGems","purl":"pkg:gem/phlex"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1"}]}],"versions":["0.1.0","0.2.0","0.2.1","0.2.2","0.3.0","0.3.1","0.3.2","0.4.0","0.5.0","0.5.1","0.5.2","0.5.3","1.0.0","1.0.0.rc1","1.0.0.rc2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}]}