VDB
Sign up
MEDIUM6.1

GHSA-3mgp-fx93-9xv5

XSS vulnerability that affects bootstrap

Quick fix

GHSA-3mgp-fx93-9xv5 — bootstrap: upgrade to the fixed version with the command below.

npm install bootstrap@3.4.0

Details

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootstrap
Introduced in: 0Fixed in: 3.4.0
Fixnpm install bootstrap@3.4.0
npm/bootstrap-sass
Introduced in: 0Fixed in: 3.4.0
Fixnpm install bootstrap-sass@3.4.0
Packagist/twbs/bootstrap
Introduced in: 0Fixed in: 3.4.0
Fixcomposer require twbs/bootstrap:^3.4.0
Maven/org.webjars:bootstrap
Introduced in: 0Fixed in: 3.4.0
Fix# pom.xml: bump <version>3.4.0</version> for org.webjars:bootstrap
RubyGems/bootstrap
Introduced in: 0Fixed in: 3.4.0
Fixbundle update bootstrap
RubyGems/bootstrap-sass
Introduced in: 0Fixed in: 3.4.0
Fixbundle update bootstrap-sass
NuGet/bootstrap
Introduced in: 0Fixed in: 3.4.0
Fixdotnet add package bootstrap --version 3.4.0

References