| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| twitter-bootstrap-rails | rubygems |
| < 3.2.0 |
| 3.2.0 |
The advisory explicitly states the vulnerability exists in the bootstrap_flash helper method's lack of input validation. As a flash message handler that directly outputs user-influenced content without sanitization, it creates an XSS vector. The description directly links this method to the vulnerability mechanism, and the patched version (3.2.0) likely adds proper sanitization here.
KEV Misses 88% of Exploited CVEs- Get the report