VYPR

RubyGems package

bootstrap-sass

pkg:gem/bootstrap-sass

Vulnerabilities (7)

  • CVE-2019-10842Apr 4, 2019
    affected >= 3.2.0.3, < 3.2.0.4fixed 3.2.0.4

    Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbit

  • CVE-2019-8331Feb 20, 2019
    affected >= 3.0.0, < 3.4.1fixed 3.4.1

    In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

  • CVE-2018-20677Jan 9, 2019
    affected < 3.4.0fixed 3.4.0

    In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

  • CVE-2018-20676Jan 9, 2019
    affected < 3.4.0fixed 3.4.0

    In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

  • CVE-2016-10735Jan 9, 2019
    affected >= 2.0.4, < 3.4.0fixed 3.4.0

    In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

  • CVE-2018-14042Jul 13, 2018
    affected >= 2.3.0, < 3.4.0fixed 3.4.0

    In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

  • CVE-2018-14040Jul 13, 2018
    affected >= 2.3.0, < 3.4.0fixed 3.4.0

    In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.