Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such, the reported behavior fell outside the scope of Bootstrap’s security model, and the associated CVE has been rescinded.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade twitter-bootstrap4 | Apr 15, 2025 | Jul 11, 2024 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.3.2Upgrade Splunk Enterprise to version 9.2.4Upgrade Splunk Enterprise to version 9.1.7 | Dec 18, 2025 | Jul 11, 2024 |
| Ubuntu | — | Upgrade libjs-bootstrap4 (Ubuntu Pro)Upgrade libjs-bootstrap (Ubuntu Pro)Upgrade libjs-bootstrap4Upgrade libjs-bootstrap | Jun 6, 2025 | Jul 11, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub