CVE-2024-6485
MediumAdvisory
Published 11 Jul 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.4
- base score, highest
- EPSS
- 0.005
- 41st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 28
- of 17,781 indexed, latest versions
- Container images
- 32
- deployed by those charts
- Fix available
- None
- affected package
Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes
Carried by container images the latest versions of 28 of 17,781 indexed charts deploy, on 32 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| bootstrapnpm | 3.1.1, 3.2.0, 3.3.4, 3.3.5+2 more | no fix listed | 32 |
- OSV records
- GHSA-vxmc-5x29-h64v
Charts affected
28 by stars
Container images carrying it
32 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| pantsel/ | c8172b75607d | bootstrap | no fix listed | 3 |
| l7mp/ | fd2b2d06fff6 | bootstrap | no fix listed | 2 |
| aristidetm/ | 469dbc951224 | bootstrap | no fix listed | 1 |
| aristidetm/ | ccb516cb8474 | bootstrap | no fix listed | 1 |
| countly/ | f4cc7447c4f5 | bootstrap | no fix listed | 1 |
| countly/ | e3c238248f99 | bootstrap | no fix listed | 1 |
| countly/ | 2acbc11499b6 | bootstrap | no fix listed | 1 |
| daskdev/ | 052630f5ca04 | bootstrap | no fix listed | 1 |
| gristlabs/ | 6e71b1914a7e | bootstrap | no fix listed | 1 |
| ibmcom/ | ed5505e5c7ec | bootstrap | no fix listed | 1 |
| jupyterhub/ | 5a0ceed1300a | bootstrap | no fix listed | 1 |
| jupyterhub/ | b6b4a1a34bf0 | bootstrap | no fix listed | 1 |
| jupyterhub/ | e4770285aaf7 | bootstrap | no fix listed | 1 |
| jupyterhub/ | 8e4778efec8e | bootstrap | no fix listed | 1 |
| jupyterhub/ | e3e6f3051df8 | bootstrap | no fix listed | 1 |
| konradkleine/ | 181aad54ee64 | bootstrap | no fix listed | 1 |
| linuxserver/ | b801bbcf6386 | bootstrap | no fix listed | 1 |
| linuxserver/ | e299a5a4f1f2 | bootstrap | no fix listed | 1 |
| lsstsqre/ | b75bf8aaafa4 | bootstrap | no fix listed | 1 |
| lsstsqre/ | 19c2dfc4e4ff | bootstrap | no fix listed | 1 |
| lsstsqre/ | 5e0ade6bed1c | bootstrap | no fix listed | 1 |
| lsstsqre/ | e9feb99f524d | bootstrap | no fix listed | 1 |
| mautic/ | eb8cc73d97e1 | bootstrap | no fix listed | 1 |
| pangeo/ | 5fbe688a4f80 | bootstrap | no fix listed | 1 |
| pedrocesarti/ | 14851f144f57 | bootstrap | no fix listed | 1 |
| phntom/ | 1b9aafbb62e6 | bootstrap | no fix listed | 1 |
| pschiffe/ | 37ebba8c2b8f | bootstrap | no fix listed | 1 |
| ghcr.io/ | ef768f3df5d0 | bootstrap | no fix listed | 1 |
| quay.io/ | 2528c6e57587 | bootstrap | no fix listed | 1 |
| quay.io/ | 65e1b09fc8c9 | bootstrap | no fix listed | 1 |
| quay.io/ | cae8c0622533 | bootstrap | no fix listed | 1 |
| quay.io/ | c973e166a5dc | bootstrap | no fix listed | 1 |