Vulnerability GHSA-vqqv-v9m2-48p2
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
7 years ago
April 04, 2019 at 04:28 PM UTC
Bootstrap-sass contains code execution backdoor
==3.2.0.3
==3.2.0.3
Summary
Bootstrap-sass contains code execution backdoor
Details
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 years ago
Bootstrap vulnerable to Cross-Site Scripting (XSS)
2.3.0.0 - 3.3.7 GHSA-3wqf-4x89-9g79
2.3.0.0 - 3.3.7 GHSA-3wqf-4x89-9g79
Medium Risk
7 years ago
Bootstrap Vulnerable to Cross-Site Scripting
3.0.0.0 - 3.4.0 GHSA-9v3m-8fp8-mj99
3.0.0.0 - 3.4.0 GHSA-9v3m-8fp8-mj99
Medium Risk
7 years ago
bootstrap Cross-site Scripting vulnerability
1.2.0 - 3.3.7 GHSA-ph58-4vrj-w6hr
1.2.0 - 3.3.7 GHSA-ph58-4vrj-w6hr
Medium Risk
7 years ago
XSS vulnerability that affects bootstrap
1.2.0 - 3.3.7 GHSA-3mgp-fx93-9xv5
1.2.0 - 3.3.7 GHSA-3mgp-fx93-9xv5
Medium Risk
7 years ago
Bootstrap Cross-site Scripting vulnerability
2.0.4.0 - 3.3.7 GHSA-4p24-vmcr-4gqj
2.0.4.0 - 3.3.7 GHSA-4p24-vmcr-4gqj
Impacted packages
Timeline
Published
7 years ago
April 04, 2019 at 04:28 PM UTC
Fixed (3.2.0.4)
7 years ago
April 03, 2019 at 04:08 PM UTC
Last Modified
6 months ago
March 13, 2026 at 10:11 PM UTC