diff --git a/Gemfile b/Gemfile
index 7f25aa46..22dc5f6e 100644
--- a/Gemfile
+++ b/Gemfile
@@ -200,6 +200,11 @@ gem 'sprockets-rails'
# for multiple speakers select on proposal/event forms
gem 'selectize-rails'
+# Nokogiri < 1.8.1 is subject to:
+# CVE-2017-0663, CVE-2017-7375, CVE-2017-7376, CVE-2017-9047, CVE-2017-9048,
+# CVE-2017-9049, CVE-2017-9050
+gem 'nokogiri', '>= 1.8.1'
+
# Use guard and spring for testing in development
group :development do
# to launch specs when files are modified
diff --git a/Gemfile.lock b/Gemfile.lock
index c6b4faa8..c140ffdf 100644
--- a/Gemfile.lock
+++ b/Gemfile.lock
@@ -290,7 +290,7 @@ GEM
mysql2 (0.4.9)
nenv (0.3.0)
netrc (0.11.0)
- nokogiri (1.8.0)
+ nokogiri (1.8.1)
mini_portile2 (~> 2.2.0)
notiffany (0.1.1)
nenv (~> 0.1)
diff --git a/app/views/conferences/_venue.html.haml b/app/views/conferences/_venue.html.haml
index 62af90c7..5aee70af 100644
--- a/app/views/conferences/_venue.html.haml
+++ b/app/views/conferences/_venue.html.haml
@@ -32,4 +32,4 @@
= @conference.venue.country_name
- if @conference.venue.website
%br
- =link_to @conference.venue.website, @conference.venue.website
+ = sanitize link_to(@conference.venue.website, @conference.venue.website)
diff --git a/app/views/conferences/_venue_map.html.haml b/app/views/conferences/_venue_map.html.haml
index b58b3053..b4326924 100644
--- a/app/views/conferences/_venue_map.html.haml
+++ b/app/views/conferences/_venue_map.html.haml
@@ -3,14 +3,14 @@
- content_for(:script_body) do
:javascript
// create a map in the "map" div, set the view to a given place and zoom
- var map = L.map('map', { scrollWheelZoom: false }).setView([#{@conference.venue.latitude}, #{@conference.venue.longitude}], 11);
+ var map = L.map('map', { scrollWheelZoom: false }).setView([#{sanitize @conference.venue.latitude}, #{sanitize @conference.venue.longitude}], 11);
// add an OpenStreetMap tile layer
L.tileLayer('//{s}.tile.openstreetmap.org/{z}/{x}/{y}.png', {
attribution: 'Map data © OpenStreetMap contributors, CC-BY-SA, Imagery © Mapbox',
maxZoom: 18
}).addTo(map);
// add a marker in the given location, attach some popup content to it and open the popup
- L.marker([#{@conference.venue.latitude}, #{@conference.venue.longitude}]).addTo(map)
+ L.marker([#{sanitize @conference.venue.latitude}, #{sanitize @conference.venue.longitude}]).addTo(map)
.bindPopup("#{popup}")
.openPopup();
// Turn scrollwheel on when user clicks
diff --git a/app/views/conferences/show.html.haml b/app/views/conferences/show.html.haml
index f94b8ee4..5022a7a1 100644
--- a/app/views/conferences/show.html.haml
+++ b/app/views/conferences/show.html.haml
@@ -82,7 +82,7 @@
- content_for :script_head do
:javascript
- var triangle_tcs = tinycolor("#{@conference.color}").monochromatic();
+ var triangle_tcs = tinycolor("#{sanitize @conference.color}").monochromatic();
var triangle_colors = triangle_tcs.map(function(t) { return t.toHexString(); });
$(function () {
$(document).ready(function() {