From e0d338ff9ee1c1b8de16b264a791cff79445ddf9 Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Mon, 13 Apr 2026 09:25:26 -0400 Subject: [PATCH 1/2] Updated twitter-bootstrap-rails advisory --- gems/twitter-bootstrap-rails/CVE-2019-8331.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/gems/twitter-bootstrap-rails/CVE-2019-8331.yml b/gems/twitter-bootstrap-rails/CVE-2019-8331.yml index 9362ca4109..0ccbc86aa5 100644 --- a/gems/twitter-bootstrap-rails/CVE-2019-8331.yml +++ b/gems/twitter-bootstrap-rails/CVE-2019-8331.yml @@ -2,7 +2,7 @@ gem: twitter-bootstrap-rails cve: 2019-8331 ghsa: 9v3m-8fp8-mj99 -url: https://blog.getbootstrap.com/2019/02/13/bootstrap-4-3-1-and-3-4-1/ +url: https://github.com/advisories/GHSA-9v3m-8fp8-mj99 title: twitter-bootstrap-rails vulnerable to Cross-Site Scripting (XSS) date: 2019-02-15 description: | @@ -23,6 +23,12 @@ description: | cvss_v2: 4.3 cvss_v3: 6.1 +patched_versions: + - ">= 5.3.0" related: url: + - https://nvd.nist.gov/vuln/detail/CVE-2019-8331 + - https://github.com/seyhunak/twitter-bootstrap-rails/releases/tag/v5.3.0 + - https://github.com/seyhunak/twitter-bootstrap-rails/commit/ec8d08af20fa3abe9852f51f7e1258fc40b39a44 - https://github.com/twbs/bootstrap-sass/releases/tag/v3.4.1 + - https://github.com/advisories/GHSA-9v3m-8fp8-mj99 From ffd1cbe99f22240bbfbe131600f1789f3d6a1ecb Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Wed, 13 May 2026 10:21:15 -0400 Subject: [PATCH 2/2] Add new reference link for CVE-2019-8331 https://blog.getbootstrap.com/2019/02/13/bootstrap-4-3-1-and-3-4-1 --- gems/twitter-bootstrap-rails/CVE-2019-8331.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/gems/twitter-bootstrap-rails/CVE-2019-8331.yml b/gems/twitter-bootstrap-rails/CVE-2019-8331.yml index 0ccbc86aa5..f78796be2b 100644 --- a/gems/twitter-bootstrap-rails/CVE-2019-8331.yml +++ b/gems/twitter-bootstrap-rails/CVE-2019-8331.yml @@ -31,4 +31,5 @@ related: - https://github.com/seyhunak/twitter-bootstrap-rails/releases/tag/v5.3.0 - https://github.com/seyhunak/twitter-bootstrap-rails/commit/ec8d08af20fa3abe9852f51f7e1258fc40b39a44 - https://github.com/twbs/bootstrap-sass/releases/tag/v3.4.1 + - https://blog.getbootstrap.com/2019/02/13/bootstrap-4-3-1-and-3-4-1 - https://github.com/advisories/GHSA-9v3m-8fp8-mj99