VDB
Sign up
MEDIUM6.1

GHSA-7mvr-5x2g-wfc8

Bootstrap Cross-site Scripting vulnerability

Quick fix

GHSA-7mvr-5x2g-wfc8 — bootstrap: upgrade to the fixed version with the command below.

bundle update bootstrap

Details

In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixbundle update bootstrap
RubyGems/bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fixbundle update bootstrap
npm/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixnpm install bootstrap@4.1.2
npm/bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fixnpm install bootstrap@3.4.0
Maven/org.webjars:bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fix# pom.xml: bump <version>4.1.2</version> for org.webjars:bootstrap
Maven/org.webjars:bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fix# pom.xml: bump <version>3.4.0</version> for org.webjars:bootstrap
Packagist/twbs/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixcomposer require twbs/bootstrap:^4.1.2
Packagist/twbs/bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fixcomposer require twbs/bootstrap:^3.4.0
NuGet/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixdotnet add package bootstrap --version 4.1.2
NuGet/bootstrap
Introduced in: 2.3.0Fixed in: 3.4.0
Fixdotnet add package bootstrap --version 3.4.0
RubyGems/bootstrap-sass
Introduced in: 2.3.0Fixed in: 3.4.0
Fixbundle update bootstrap-sass
npm/bootstrap-sass
Introduced in: 2.0.4Fixed in: 3.4.0
Fixnpm install bootstrap-sass@3.4.0
NuGet/bootstrap.sass
Introduced in: 4.0.0Fixed in: 4.1.2
Fixdotnet add package bootstrap.sass --version 4.1.2

References