CVE-2014-4920
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
描述
The twitter-bootstrap-rails Gem for Rails contains a flaw that enables a reflected cross-site scripting (XSS) attack. This flaw exists because the bootstrap_flash helper method does not validate input when handling flash messages before returning it to users. This may allow a context-dependent attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server.
如何修補 CVE-2014-4920
要修補 CVE-2014-4920,請將受影響套件升級到下列已修補版本。
- RubyGems/twitter-bootstrap-rails—升級至 3.2.0 或更新版本
CVE-2014-4920 正在被利用嗎?
目前沒有被利用訊號。CVE-2014-4920 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- from 0, < 3.2.0