Skip to main content

Supported Ruby cleansing functions

FunctionFlaw class
base64.!class.encode64CWE-80, 93, 113, and 117
base64.!class.strict_encode64CWE-80, 93, 113, and 117
base64.!class.urlsafe_encode64CWE-80, 93, 113, and 117
CGI.!class.escapeCWE-80, 93, 113, and 117
CGI.!class.escapeHTMLCWE-80
CGI.!class.escape_htmlCWE-80
digest.class.!class.base64digestCWE-80, 93, 113, and 117
ERB.Util.!class.hCWE-80, 93, 113, and 117
ERB.Util.!class.html_escapeCWE-80, 93, 113, and 117
ERB.Util.!class.uCWE-80, 93, 113, and 117
ERB.Util.!class.url_encodeCWE-80, 93, 113, and 117
RSS.Converter.hCWE-80, 93, 113, and 117
RSS.Converter.html_escapeCWE-80, 93, 113, and 117
RSS.Element.hCWE-80, 93, 113, and 117
RSS.Element.html_escapeCWE-80, 93, 113, and 117
shellwords.!class.escapeCWE-80, 93, 113, and 117
shellwords.!class.shellescapeCWE-80, 93, 113, and 117
string.shellescape()CWE-80, 93, 113, and 117
URI.!class.encode_www_formCWE-80, 93, 113, and 117
URI.!class.encode_www_form_componentCWE-80, 93, 113, and 117
URI.Parser.escapeCWE-80, 93, 113, and 117
WEBrick.HTMLUtils.escapeCWE-80, 93, 113, and 117
WEBrick.HTTPUtils.!class.escape_formCWE-80, 93, 113, and 117
WEBrick.HTTPUtils.!class.escape_pathCWE-80, 93, 113, and 117
XMLRPC.Base64.!class.encodeCWE-80, 93, 113, and 117
XMLRPC.Base64.encodeCWE-80, 93, 113, and 117