// For flags

CVE-2019-10842

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare.

Se ha descubierto una ejecución de código arbitrario (mediante código de puerta trasera) en bootstrap-sass 3.2.0.3, cuando se descarga desde rubygems.org. Un atacante no autenticado puede manipular el valor de la cookie ___cfduid con código arbitrario base64 para que se ejecute mediante eval(). Esto puede explotarse para ejecutar código arbitrario en el sistema objetivo. Nótese que hay tres guiones bajos en el nombre de la cookie. Esto no está relacionado con la cookie __cfduid que Cloudflare usa de manera legítima.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-04-03 CVE Reserved
  • 2019-04-04 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-10-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Getbootstrap
Search vendor "Getbootstrap"
Bootstrap-sass
Search vendor "Getbootstrap" for product "Bootstrap-sass"
3.2.0.3
Search vendor "Getbootstrap" for product "Bootstrap-sass" and version "3.2.0.3"
ruby
Affected