ruby-sanitize (4.6.6-2.1~0.20.04.2) focal-security; urgency=medium * SECURITY UPDATE: XSS via style element when using "relaxed" or custom config - debian/patches/CVE-2023-36823.patch: prevent style element from premature close by escaping "</" in lib/sanitize/transformers/clean_css.rb. - CVE-2023-36823 -- Evan Caville <email address hidden> Fri, 19 Apr 2024 12:42:19 +1000