MEDIUM 6.4 Microsoft
CVE-2024-6531
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
Microsoft Security Update 2024-Jul: Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
Affected Products
- cbl2 opa 0.63.0-4 on CBL Mariner 2.0
- cbl2 prometheus 2.37.9-5 on CBL Mariner 2.0
- cbl2 prometheus 2.37.9-6 on CBL Mariner 2.0
- cbl2 prometheus 2.37.9-4 on CBL Mariner 2.0
- cbl2 opa 0.63.0-5 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-6531
- https://nvd.nist.gov/vuln/detail/CVE-2024-6531
This medium severity vulnerability with a CVSS score of 6.4 was published on 2024-07-09 via Microsoft. Affected: cbl2 opa 0.63.0-4 on CBL Mariner 2.0, cbl2 prometheus 2.37.9-5 on CBL Mariner 2.0, cbl2 prometheus 2.37.9-6 on CBL Mariner 2.0 and 2 more.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.