VDB
Sign up
MEDIUM6.1

GHSA-3wqf-4x89-9g79

Bootstrap vulnerable to Cross-Site Scripting (XSS)

Quick fix

GHSA-3wqf-4x89-9g79 — bootstrap: upgrade to the fixed version with the command below.

npm install bootstrap@4.1.2

Details

In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixnpm install bootstrap@4.1.2
RubyGems/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixbundle update bootstrap
npm/bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fixnpm install bootstrap@3.4.0
RubyGems/bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fixbundle update bootstrap
Maven/org.webjars:bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fix# pom.xml: bump <version>4.1.2</version> for org.webjars:bootstrap
Maven/org.webjars:bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fix# pom.xml: bump <version>3.4.0</version> for org.webjars:bootstrap
NuGet/bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fixdotnet add package bootstrap --version 3.4.0
NuGet/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixdotnet add package bootstrap --version 4.1.2
NuGet/bootstrap.sass
Introduced in: 4.0.0Fixed in: 4.1.2
Fixdotnet add package bootstrap.sass --version 4.1.2
RubyGems/bootstrap-sass
Introduced in: 2.3.0Fixed in: 3.4.0
Fixbundle update bootstrap-sass
Packagist/twbs/bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fixcomposer require twbs/bootstrap:^3.4.0
Packagist/twbs/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixcomposer require twbs/bootstrap:^4.1.2

References