Launchpad.net

CVE 2018-8048

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

See the CVE page on Mitre.org for more details.