SCA: security update for bootstrap-sass (GHSA-vqqv-v9m2-48p2)

critical Tenable Self-Hosted Container Security Plugin ID 422911

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded
from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary
code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system.
Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid
cookie that is legitimately used by Cloudflare. (CVE-2019-10842)

See Also

https://github.com/advisories/GHSA-vqqv-v9m2-48p2

Plugin Details

Severity: Critical

ID: 422911

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 3/29/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2019-10842

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/4/2019

Vulnerability Publication Date: 3/27/2019

Reference Information

CVE: CVE-2019-10842

BID: 108468

cwe: CWE-94