Vulnerability GHSA-vpqv-mqvc-pcx2

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 years ago
March 16, 2023 at 06:35 PM UTC
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
0.0.3 - 2.0 and 2.0.0 - 2.0.1 and 2.0.1.0 - 2.2.8
0.0.3 - 2.0 and 2.0.0 - 2.0.1 and 2.0.1.0 - 2.2.8

Summary

Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails

Details

The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server.

Impacted packages

Timeline

Published
3 years ago
March 16, 2023 at 06:35 PM UTC
Fixed (3.2.0)
12 years ago
August 11, 2014 at 07:53 AM UTC
Last Modified
1 year ago
November 30, 2024 at 05:34 AM UTC