CVE-2019-10842
Last modified
CVE-2019-10842 is a vulnerability of currently unknown severity. Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. EPSS estimates a 4.92% chance of exploitation in the next 30 days.
Description
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Getbootstrap | Bootstrap-Sass | 3.2.0.3 |
References
- http://dgb.github.io/2019/04/05/bootstrap-sass-backdoor.htmlThird Party Advisory
- https://github.com/twbs/bootstrap-sass/issues/1195Issue Tracking, Third Party Advisory
- https://snyk.io/blog/malicious-remote-code-execution-backdoor-discovered-in-the-popular-bootstrap-sass-ruby-gem/Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-RUBY-BOOTSTRAPSASS-174093Exploit, Third Party Advisory
- http://dgb.github.io/2019/04/05/bootstrap-sass-backdoor.htmlThird Party Advisory
- https://github.com/twbs/bootstrap-sass/issues/1195Issue Tracking, Third Party Advisory
- https://snyk.io/blog/malicious-remote-code-execution-backdoor-discovered-in-the-popular-bootstrap-sass-ruby-gem/Exploit, Third Party Advisory
- https://snyk.io/vuln/SNYK-RUBY-BOOTSTRAPSASS-174093Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10842?
How severe is CVE-2019-10842?
How do I fix CVE-2019-10842?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10807Blamer versions prior to 1.0.1 allows execution of arbitrary…9.8
- CVE-2019-10808utilitify prior to 1.0.3 allows modification of object prope…8.8
- CVE-2019-1081An information disclosure vulnerability exists when affected…4.2
- CVE-2019-1082An elevation of privilege vulnerability exists in Microsoft …
- CVE-2019-1083A denial of service vulnerability exists when Microsoft Comm…
- CVE-2019-1084An information disclosure vulnerability exists when Exchange…
- CVE-2019-10843Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-10844nbla/logger.cpp in libnnabla.a in Sony Neural Network Librar…
- CVE-2019-10845An issue was discovered in Uniqkey Password Manager 1.14. Wh…
- CVE-2019-10846Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cros…6.1
- CVE-2019-10847Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
- CVE-2019-10848Computrols CBAS 18.0.0 allows Username Enumeration.
Are you affected by CVE-2019-10842?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
