CVE-2024-6484

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-6484
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6484.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6484
Aliases
Downstream
Withdrawn
2025-08-02T12:55:49.635864Z
Published
2024-07-11T17:15:17Z
Modified
2025-08-01T19:54:48.241444Z
Summary
[none]
Details

Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.

References

Affected packages

Debian:11 / twitter-bootstrap3

Package

Name
twitter-bootstrap3
Purl
pkg:deb/debian/twitter-bootstrap3?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.1+dfsg-2+deb11u1

Affected versions

3.*

3.4.1+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / twitter-bootstrap3

Package

Name
twitter-bootstrap3
Purl
pkg:deb/debian/twitter-bootstrap3?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.1+dfsg-3+deb12u1

Affected versions

3.*

3.4.1+dfsg-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / twitter-bootstrap3

Package

Name
twitter-bootstrap3
Purl
pkg:deb/debian/twitter-bootstrap3?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.1+dfsg-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/twbs/bootstrap

Affected ranges

Type
GIT
Repo
https://github.com/twbs/bootstrap
Events

Affected versions

v3.*

v3.2.0
v3.3.0
v3.3.1
v3.3.2
v3.3.4
v3.3.5
v3.3.6
v3.3.7
v3.4.0
v3.4.1