CVE-2019-1195
published 2019-08-14CVE-2019-1195: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The…
PriorityP426medium4.2CVSS 3.1
AVNACHPRNUIRSUCLILAN
EPSS
1.88%
77.1th percentile
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (HTML-based) and then convince a user to view the website. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability.
The security update addresses the vulnerability by modifying how the Chakra scripting engine handles objects in memory.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | chakracore | < publication | publication |
| microsoft | microsoft_edge | >= 1.0..0 < publication | publication |
| msrc | chakracore | — | — |
| msrc | microsoft_edge_on_windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1709_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1709_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1709_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1903_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1903_for_arm64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1903_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_server_2016 | — | — |
| msrc | microsoft_edge_on_windows_server_2019 | — | — |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
ghsa4.2MEDIUM
osv4.2MEDIUM
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Out-of-bounds write
ghsa·2021-03-29·CVSS 4.2
CVE-2019-1197 [MEDIUM] CWE-787 Out-of-bounds write
Out-of-bounds write
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196.
OSV
Out-of-bounds write in Microsoft.ChakraCore
osv·2021-03-29·CVSS 4.2
CVE-2019-1195 [MEDIUM] Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1141, CVE-2019-1196, CVE-2019-1197.
GHSA
Out-of-bounds write in Microsoft.ChakraCore
ghsa·2021-03-29·CVSS 4.2
CVE-2019-1131 [MEDIUM] CWE-787 Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1139, CVE-2019-1140, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
GHSA
Out-of-bounds write in ChakraCore
ghsa·2021-03-29·CVSS 4.2
CVE-2019-1196 [MEDIUM] CWE-787 Out-of-bounds write in ChakraCore
Out-of-bounds write in ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1141, CVE-2019-1195, CVE-2019-1197.
OSV
Out-of-bounds write in Microsoft.ChakraCore
osv·2021-03-29·CVSS 4.2
CVE-2019-1141 [MEDIUM] Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
OSV
Out-of-bounds write
osv·2021-03-29·CVSS 4.2
CVE-2019-1197 [MEDIUM] Out-of-bounds write
Out-of-bounds write
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196.
GHSA
Out-of-bounds write in Microsoft.ChakraCore
ghsa·2021-03-29·CVSS 4.2
CVE-2019-1140 [MEDIUM] CWE-787 Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
OSV
Out-of-bounds write in ChakraCore
osv·2021-03-29·CVSS 4.2
CVE-2019-1196 [MEDIUM] Out-of-bounds write in ChakraCore
Out-of-bounds write in ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1141, CVE-2019-1195, CVE-2019-1197.
GHSA
Out-of-bounds write in Microsoft.ChakraCore
ghsa·2021-03-29·CVSS 4.2
CVE-2019-1195 [MEDIUM] CWE-787 Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1141, CVE-2019-1196, CVE-2019-1197.
GHSA
Out-of-bounds write in Microsoft.ChakraCore
ghsa·2021-03-29·CVSS 4.2
CVE-2019-1139 [MEDIUM] CWE-787 Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1140, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
GHSA
Out-of-bounds write in Microsoft.ChakraCore
ghsa·2021-03-29·CVSS 4.2
CVE-2019-1141 [MEDIUM] CWE-787 Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1140, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
OSV
Out-of-bounds write in Microsoft.ChakraCore
osv·2021-03-29·CVSS 4.2
CVE-2019-1139 [MEDIUM] Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1140, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
OSV
Out-of-bounds write in Microsoft.ChakraCore
osv·2021-03-29·CVSS 4.2
CVE-2019-1131 [MEDIUM] Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1139, CVE-2019-1140, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
OSV
Out-of-bounds write in Microsoft.ChakraCore
osv·2021-03-29·CVSS 4.2
CVE-2019-1140 [MEDIUM] Out-of-bounds write in Microsoft.ChakraCore
Out-of-bounds write in Microsoft.ChakraCore
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1131, CVE-2019-1139, CVE-2019-1141, CVE-2019-1195, CVE-2019-1196, CVE-2019-1197.
Microsoft
Chakra Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2019-08-13·CVSS 4.2
CVE-2019-1195 [MEDIUM] Chakra Scripting Engine Memory Corruption Vulnerability
Chakra Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a
No detection rules found.
No public exploits indexed.
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
# August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro
Aug 14, 2019
Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time of release, a few of the bu
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
# August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro
2019/08/14
Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time o
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Ausnutzung von Schwachstellen
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the t
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits y vulnerabilidades
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the tim
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time of release, a few of the bu
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro 2019/08/14 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time o
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Sfruttamento vulnerabilità
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.1
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here, covering all of the new rules we have for this release.
### Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2019-1181 and CVE-2019-1182 are both remote code execution vulnerabilities in Remote De
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here , covering all of the new rules we have for this release.
## Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2
Zscaler
Zscaler found Multiple Security Vulnerabilities | 08-14-2019
blogs_zscaler·CVSS 4.2
[MEDIUM] Zscaler found Multiple Security Vulnerabilities | 08-14-2019
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2019-10842 rubygem-bootstrap-sass: backdoor code allows arbitrary code execution when downloaded from rubygems.org
bugzilla·2019-04-08·CVSS 9.8
CVE-2019-10842 [CRITICAL] CVE-2019-10842 rubygem-bootstrap-sass: backdoor code allows arbitrary code execution when downloaded from rubygems.org
CVE-2019-10842 rubygem-bootstrap-sass: backdoor code allows arbitrary code execution when downloaded from rubygems.org
Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare.
Upstream issue:
https://github.com/twbs/bootstrap-sass/issues/1195
References:
https://snyk.io/blog/malicious-remote-code-execution-backdoor-discovered-in-the-popular-bootstrap-sass-ruby-gem/
https://snyk.io/vuln/SN
2019-08-14
Published