MEDIUM6.1
GHSA-7mvr-5x2g-wfc8
Bootstrap Cross-site Scripting vulnerability
Quick fix
GHSA-7mvr-5x2g-wfc8 — bootstrap: upgrade to the fixed version with the command below.
bundle update bootstrapDetails
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.webjars:bootstrap
Introduced in:
4.0.0Fixed in: 4.1.2Fix
# pom.xml: bump <version>4.1.2</version> for org.webjars:bootstrapMaven/org.webjars:bootstrap
Introduced in:
2.3.0Fixed in: 3.4.0Fix
# pom.xml: bump <version>3.4.0</version> for org.webjars:bootstrapPackagist/twbs/bootstrap
Introduced in:
4.0.0Fixed in: 4.1.2Fix
composer require twbs/bootstrap:^4.1.2Packagist/twbs/bootstrap
Introduced in:
2.3.0Fixed in: 3.4.0Fix
composer require twbs/bootstrap:^3.4.0NuGet/bootstrap.sass
Introduced in:
4.0.0Fixed in: 4.1.2Fix
dotnet add package bootstrap.sass --version 4.1.2References
- https://nvd.nist.gov/vuln/detail/CVE-2018-14042[ADVISORY]
- https://github.com/twbs/bootstrap/issues/26423[WEB]
- https://github.com/twbs/bootstrap/issues/26428[WEB]
- https://github.com/twbs/bootstrap/issues/26628[WEB]
- https://github.com/twbs/bootstrap/pull/26630[WEB]
- https://github.com/twbs/bootstrap/commit/2a5ba23ce8f041f3548317acc992ed8a736b609d[WEB]
- https://github.com/twbs/bootstrap/commit/2d90d369bbc2bd2647620246c55cec8c4705e3d0[WEB]
- https://www.tenable.com/security/tns-2021-14[WEB]
- https://www.oracle.com/security-alerts/cpuApr2021.html[WEB]
- https://seclists.org/bugtraq/2019/May/18[WEB]
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r3dc0cac8d856bca02bd6997355d7ff83027dcfc82f8646a29b89b714@%3Cissues.hbase.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e@%3Cdev.superset.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E[WEB]
- https://github.com/twbs/bootstrap[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bootstrap/CVE-2018-14042.yml[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bootstrap-sass/CVE-2018-14042.yml[WEB]
- https://github.com/advisories/GHSA-7mvr-5x2g-wfc8[ADVISORY]
- https://blog.getbootstrap.com/2018/07/12/bootstrap-4-1-2[WEB]
- http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html[WEB]
- http://seclists.org/fulldisclosure/2019/May/10[WEB]
- http://seclists.org/fulldisclosure/2019/May/11[WEB]
- http://seclists.org/fulldisclosure/2019/May/13[WEB]