CVE-2019-10842
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare.
Se ha descubierto una ejecución de código arbitrario (mediante código de puerta trasera) en bootstrap-sass 3.2.0.3, cuando se descarga desde rubygems.org. Un atacante no autenticado puede manipular el valor de la cookie ___cfduid con código arbitrario base64 para que se ejecute mediante eval(). Esto puede explotarse para ejecutar código arbitrario en el sistema objetivo. Nótese que hay tres guiones bajos en el nombre de la cookie. Esto no está relacionado con la cookie __cfduid que Cloudflare usa de manera legítima.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-03 CVE Reserved
- 2019-04-04 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-10-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://dgb.github.io/2019/04/05/bootstrap-sass-backdoor.html | Third Party Advisory | |
https://github.com/twbs/bootstrap-sass/issues/1195 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://snyk.io/blog/malicious-remote-code-execution-backdoor-discovered-in-the-popular-bootstrap-sass-ruby-gem | 2024-08-04 | |
https://snyk.io/vuln/SNYK-RUBY-BOOTSTRAPSASS-174093 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Getbootstrap Search vendor "Getbootstrap" | Bootstrap-sass Search vendor "Getbootstrap" for product "Bootstrap-sass" | 3.2.0.3 Search vendor "Getbootstrap" for product "Bootstrap-sass" and version "3.2.0.3" | ruby |
Affected
|