StackRadar

CVE-2019-8331

Medium

Advisory

Published 22 Feb 2019In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.164
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
3 of 3
affected packages

Bootstrap Vulnerable to Cross-Site Scripting

Carried by container images the latest versions of 22 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
bootstrapnpm3.1.1, 3.2.0, 3.3.2, 3.3.4+5 more3.4.1, 4.3.115
bootstrapmaven3.3.5, 3.3.6, 3.3.7-13.4.13
twbs/bootstrapcomposerv4.1.04.3.11
OSV records
GHSA-9v3m-8fp8-mj99

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
spring-petclinic-cloudplatform9-communityVerified publisher0.2.01 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

1 of the 6 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
platform9community/api-gateway:latest40a4970de568
bootstrap@3.3.7-1
3.4.1

Open the chart page →

41,872
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
bootstrap@3.3.7
3.4.1

Open the chart page →

5,209
distributed-jmetercloudnativeapp1.0.11 of 1See more

distributed-jmeter cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
pedrocesarti/jmeter-docker:3.314851f144f57
bootstrap@3.3.4
3.4.1

Open the chart page →

4,532
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
bootstrap@3.3.2
3.4.1

Open the chart page →

2,519
kafka-managerradar-baseVerified publisher2.3.11 of 1See more

kafka-manager radar-base 2.3.1

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
radarbase/kafka-manager:1.3.3.181d2af7dd5a4e
bootstrap@3.3.5
3.4.1

Open the chart page →

4,000
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
bootstrap@3.3.7
3.4.1

Open the chart page →

18,277
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
bootstrap@3.3.4
3.4.1

Open the chart page →

4,069
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
bootstrap@3.3.7
3.4.1

Open the chart page →

29,901
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
bootstrap@3.3.7
3.4.1

Open the chart page →

5,209
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
bootstrap@4.0.0
4.3.1

Open the chart page →

1,043
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
governify/render:v2.2.0daeca1ce28e6
bootstrap@4.1.1
4.3.1

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
governify/render:v2.2.0daeca1ce28e6
bootstrap@4.1.1
4.3.1

Open the chart page →

24,319
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
bootstrap@3.3.4
3.4.1

Open the chart page →

57,669
fossologymidokura-communityVerified publisher0.2.21 of 2See more

fossology midokura-community 0.2.2

1 of the 2 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
fossology/fossology:4.2.18bd1f22ba7bb
bootstrap@4.1.0
twbs/bootstrap@v4.1.0
4.3.1
4.3.1

Open the chart page →

3,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
bootstrap@3.1.1
3.4.1

Open the chart page →

27,465
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
bootstrap@3.1.1
3.4.1

Open the chart page →

6,524
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
bootstrap@3.1.1
3.4.1

Open the chart page →

4,616
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
bootstrap@3.3.5
3.4.1

Open the chart page →

5,215
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
bootstrap@3.3.6
3.4.1

Open the chart page →

6,101
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
bootstrap@3.3.7
3.4.1

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
bootstrap@3.3.7
3.4.1

Open the chart page →

12,460
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2019-8331.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
bootstrap@3.2.0
3.4.1

Open the chart page →

3,827

Container images carrying it

18 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
bootstrap@3.3.7
3.4.1
3
governify/render:v2.2.0daeca1ce28e6
bootstrap@4.1.1
4.3.1
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
bootstrap@3.3.7
3.4.1
2
daskdev/dask-notebook:1.1.0052630f5ca04
bootstrap@3.3.7
3.4.1
1
fossology/fossology:4.2.18bd1f22ba7bb
bootstrap@4.1.0
twbs/bootstrap@v4.1.0
4.3.1
4.3.1
1
gristlabs/grist:0.7.96e71b1914a7e
bootstrap@3.3.5
3.4.1
1
ibmcom/microclimate-portal:latested5505e5c7ec
bootstrap@3.3.4
3.4.1
1
konradkleine/docker-registry-frontend:v2181aad54ee64
bootstrap@3.3.4
3.4.1
1
linuxserver/codimd:latestb801bbcf6386
bootstrap@3.1.1
3.4.1
1
linuxserver/grocy:version-v3.1.3291296e66c2a
bootstrap@4.0.0
4.3.1
1
pedrocesarti/jmeter-docker:3.314851f144f57
bootstrap@3.3.4
3.4.1
1
phntom/codimd:2.4.31b9aafbb62e6
bootstrap@3.1.1
3.4.1
1
platform9community/api-gateway:latest40a4970de568
bootstrap@3.3.7-1
3.4.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
bootstrap@3.1.1
3.4.1
1
radarbase/kafka-manager:1.3.3.181d2af7dd5a4e
bootstrap@3.3.5
3.4.1
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
bootstrap@3.3.2
3.4.1
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
bootstrap@3.3.6
3.4.1
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
bootstrap@3.2.0
3.4.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.