Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS12cHF2LW1xdmMtcGN4Ms4AAyKB

Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails

The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a
reflected cross-site scripting (XSS) attack. This flaw exists because the
bootstrap_flash helper method does not validate input when handling flash
messages before returning it to users. This may allow a context-dependent
attacker to create a specially crafted request that would execute arbitrary
script code in a user's browser session within the trust relationship between
their browser and the server.

Permalink: https://github.com/advisories/GHSA-vpqv-mqvc-pcx2
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cHF2LW1xdmMtcGN4Ms4AAyKB
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 1 year ago
Updated: about 1 year ago


Identifiers: GHSA-vpqv-mqvc-pcx2, CVE-2014-4920
References: Blast Radius: 0.0

Affected Packages

rubygems:twitter-bootstrap-rails
Dependent packages: 83
Dependent repositories: 27,499
Downloads: 9,355,192 total
Affected Version Ranges: < 3.2.0
Fixed in: 3.2.0
All affected versions: 0.0.3, 0.0.4, 0.0.5, 1.3.0, 1.3.1, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9, 2.2.0, 2.2.1, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8
All unaffected versions: 3.2.0, 3.2.2, 4.0.0, 5.0.0