
CVE-2019-10842
https://notcve.org/view.php?id=CVE-2019-10842
04 Apr 2019 — Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare. Se ha descubierto una ejecución de código arbitrar... • http://dgb.github.io/2019/04/05/bootstrap-sass-backdoor.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2019-8331 – bootstrap: XSS in the tooltip or popover data-template attribute
https://notcve.org/view.php?id=CVE-2019-8331
20 Feb 2019 — In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. En Bootstrap, en versiones anteriores a la 3.4.1 y versiones 4.3.x anteriores a la 4.3.1, es posible Cross-Site Scripting (XSS) en los atributos de data-template tooltip o popover. A cross-site scripting vulnerability was discovered in bootstrap. If an attacker could control the data given to tooltip or popover, they could inject HTML or Javascript into the rendered page when tooltip or popov... • https://github.com/Thampakon/CVE-2019-8331 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-20676 – bootstrap: XSS in the tooltip data-viewport attribute
https://notcve.org/view.php?id=CVE-2018-20676
09 Jan 2019 — In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. En Bootstrap, en versiones anteriores a la 3.4.0, Cross-Site Scripting (XSS) es posible en el atributo "data-viewport". A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting, caused by improper validation of user-supplied input by the tooltip data-viewport attribute. This flaw allows a remote attacker to execute a script in a victim's Web browser within the security context of the hosting Web site, whi... • https://github.com/ossf-cve-benchmark/CVE-2018-20676 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-20677 – bootstrap: XSS in the affix configuration target property
https://notcve.org/view.php?id=CVE-2018-20677
09 Jan 2019 — In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. En Bootstrap, en versiones anteriores a la 3.4.0, Cross-Site Scripting (XSS) es posible en la propiedad "affix" en la configuración. A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting caused by improper validation of user-supplied input by the affix configuration target property. This flaw allows a remote attacker to execute a script in a victim's Web browser within the security context of the h... • https://github.com/ossf-cve-benchmark/CVE-2018-20677 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-10735 – bootstrap: XSS in the data-target attribute
https://notcve.org/view.php?id=CVE-2016-10735
09 Jan 2019 — In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041. En las versiones de Bootstrap anteriores a la 3.4.0 y en las 4.x-beta anteriores a la 4.0.0-beta.2, Cross-Site Scripting (XSS) es posible en el atributo "data-target". Se trata de una vulnerabilidad diferente de CVE-2018-14041. Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. T... • https://github.com/ossf-cve-benchmark/CVE-2016-10735 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-14040 – bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
https://notcve.org/view.php?id=CVE-2018-14040
13 Jul 2018 — In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. En Bootstrap en versiones anteriores a la 4.1.2, es posible Cross-Site Scripting (XSS) en el atributo collapse data-parent. Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.9 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.8, and includes bug fixes and enha... • https://github.com/ossf-cve-benchmark/CVE-2018-14040 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-14041 – bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy
https://notcve.org/view.php?id=CVE-2018-14041
13 Jul 2018 — In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. En Bootstrap en versiones anteriores a la 4.1.2, es posible Cross-Site Scripting (XSS) en la propiedad data-target de scrollspy. A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting, caused by improper validation of user-supplied input by the data-target property of scrollspy. This flaw allows a remote attacker to execute a script in a victim's Web browser within the security context of the hosting ... • https://github.com/ossf-cve-benchmark/CVE-2018-14041 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2018-14042 – bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip
https://notcve.org/view.php?id=CVE-2018-14042
13 Jul 2018 — In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. En Bootstrap en versiones anteriores a la 4.1.2, es posible Cross-Site Scripting (XSS) en la propiedad data-container de tooltip. Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.9 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.8, and includes bug fixe... • https://github.com/ossf-cve-benchmark/CVE-2018-14042 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •