VYPR

RubyGems package

twitter-bootstrap-rails

pkg:gem/twitter-bootstrap-rails

Vulnerabilities (2)

  • CVE-2014-4920medMar 16, 2023
    affected < 3.2.0fixed 3.2.0

    The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a con

  • CVE-2019-8331Feb 20, 2019
    affected <= 5.0.0

    In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.