In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.Referenceshttps://github.com/flavorjones/loofah/issues/144http://www.openwall.com/lists/oss-security/2018/03/19/5https://www.debian.org/security/2018/dsa-4171https://security.netapp.com/advisory/ntap-20191122-0003/