Changelog for
ruby2.5-rubygem-rails-html-sanitizer-1.0.4-150000.4.6.1.x86_64.rpm :
* Thu Aug 31 2023 paolo.peregoAATTsuse.com- Fixing typos in CVEs corrected by prior submission
* Wed Aug 30 2023 paolo.peregoAATTsuse.com- Add patch 0002_CVE-2022-23517_CVE-2022-23518_CVE-2022-23519_CVE-2022-23520.patch This patch fixes 4 different CVEs:
* CVE-2022-23517 (bsc#1206433)
* CVE-2022-23518 (bsc#1206434)
* CVE-2022-23519 (bsc#1206435)
* CVE-2022-23520 (bsc#1206436) In order to have the 0002_CVE-2022-23517_CVE-2022-23518_CVE-2022-23519_CVE-2022-23520.patch working smoothly I monkey patched loofah API and crass rubygem code into rails-html-sanitizer.
* Thu Aug 18 2022 mschnitzerAATTsuse.com- Add patch 0001_CVE-2022-32209.patch This patch fixes CVE-2022-32209 (bsc#1201183)
* Fri Mar 23 2018 dkangAATTsuse.com- updated to version 1.0.4
* CVE-2018-3741: XSS vulnerability see installed CHANGELOG.md fix bsc#1086598
* Tue Jan 26 2016 cooloAATTsuse.com- updated to version 1.0.3:
* boo#963326: CVE-2015-7578: XSS vulnerability via attributes
* boo#963327: CVE-2015-7579: XSS vulnerability
* boo#963328: CVE-2015-7580: XSS via whitelist sanitizer
* Mon Mar 16 2015 cooloAATTsuse.com- updated to version 1.0.2, no changelog
* Mon Feb 09 2015 cooloAATTsuse.com- initial package (version 1.0.1)