VDB
Sign up
MEDIUM6.1

GHSA-4p24-vmcr-4gqj

Bootstrap Cross-site Scripting vulnerability

Quick fix

GHSA-4p24-vmcr-4gqj — bootstrap: upgrade to the fixed version with the command below.

npm install bootstrap@3.4.0

Details

In Bootstrap 2.x from 2.0.4, 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041.

See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootstrap
Introduced in: 2.0.4Fixed in: 3.4.0
Fixnpm install bootstrap@3.4.0
npm/bootstrap
Introduced in: 4.0.0-betaFixed in: 4.0.0-beta.2
Fixnpm install bootstrap@4.0.0-beta.2
Maven/org.webjars:bootstrap
Introduced in: 2.0.4Fixed in: 3.4.0
Fix# pom.xml: bump <version>3.4.0</version> for org.webjars:bootstrap
Maven/org.webjars:bootstrap
Introduced in: 4.0.0-betaFixed in: 4.0.0-beta.2
Fix# pom.xml: bump <version>4.0.0-beta.2</version> for org.webjars:bootstrap
RubyGems/bootstrap
Introduced in: 0Fixed in: 4.0.0-beta.2
Fixbundle update bootstrap
Packagist/twbs/bootstrap
Introduced in: 2.0.4Fixed in: 3.4.0
Fixcomposer require twbs/bootstrap:^3.4.0
Packagist/twbs/bootstrap
Introduced in: 4.0.0-betaFixed in: 4.0.0-beta.2
Fixcomposer require twbs/bootstrap:^4.0.0-beta.2
NuGet/bootstrap
Introduced in: 2.0.4Fixed in: 3.4.0
Fixdotnet add package bootstrap --version 3.4.0
NuGet/bootstrap
Introduced in: 4.0.0-betaFixed in: 4.0.0-beta.2
Fixdotnet add package bootstrap --version 4.0.0-beta.2
npm/bootstrap-sass
Introduced in: 2.0.4Fixed in: 3.4.0
Fixnpm install bootstrap-sass@3.4.0
RubyGems/bootstrap-sass
Introduced in: 2.0.4Fixed in: 3.4.0
Fixbundle update bootstrap-sass
NuGet/bootstrap.sass
Introduced in: 4.0.0-betaFixed in: 4.0.0-beta.2
Fixdotnet add package bootstrap.sass --version 4.0.0-beta.2

References