bootstrap-sass
RubyGems7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting bootstrap-sasspage 1 of 1
- CVE-2016-10735MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02019-01-09
vulnerable: 2.0.4.0 ... 3.3.7 (42 versions)
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
- CVE-2018-14040MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02018-07-13
vulnerable: 2.3.0.0 ... 3.3.7 (33 versions)
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
- CVE-2018-14042MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02018-07-13
vulnerable: 2.3.0.0 ... 3.3.7 (33 versions)
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
- CVE-2018-20676MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02019-01-09
vulnerable: 1.2.0 ... 3.3.7 (57 versions)
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
- CVE-2018-20677MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02019-01-09
vulnerable: 1.2.0 ... 3.3.7 (57 versions)
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
- CVE-2019-10842CRITICALCVSS 9.8EG 9.8fixed in 3.2.0.42019-04-04
vulnerable: 3.2.0.3
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval()…
- CVE-2019-8331MEDIUMCVSS 6.1EG 6.1fixed in 3.4.12019-02-20
vulnerable: 3.0.0.0 ... 3.4.0 (24 versions)
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Check whether bootstrap-sass is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for bootstrap-sass CVEs against the assets you own.
Book a Demo →