LOW 3.9 Microsoft
CVE-2024-6484
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
Microsoft Security Update 2024-Jul: Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
Affected Products
- azl3 ntopng 5.2.1-5 on Azure Linux 3.0
- azl3 pytorch 2.2.2-7 on Azure Linux 3.0
- azl3 fluent-bit 3.1.9-4 on Azure Linux 3.0
- azl3 ceph 18.2.2-8 on Azure Linux 3.0
- cbl2 reaper 3.1.1-19 on CBL Mariner 2.0
- cbl2 ntopng 5.2.1-2 on CBL Mariner 2.0
- cbl2 fmt 8.1.1-1 on CBL Mariner 2.0
- cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-6484
- https://nvd.nist.gov/vuln/detail/CVE-2024-6484
This low severity vulnerability with a CVSS score of 3.9 was published on 2024-07-09 via Microsoft. Affected: azl3 ntopng 5.2.1-5 on Azure Linux 3.0, azl3 pytorch 2.2.2-7 on Azure Linux 3.0, azl3 fluent-bit 3.1.9-4 on Azure Linux 3.0 and 5 more.
vulnfeed aggregates 10103 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.