VDB
Sign up
MEDIUM6.1

GHSA-pj7m-g53m-7638

Bootstrap Cross-site Scripting vulnerability

Quick fix

GHSA-pj7m-g53m-7638 — bootstrap: upgrade to the fixed version with the command below.

npm install bootstrap@4.1.2

Details

In Bootstrap 4.x before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixnpm install bootstrap@4.1.2
Packagist/typo3/cms-core
Introduced in: 8.0.0Fixed in: 8.7.23
Fixcomposer require typo3/cms-core:^8.7.23
Packagist/typo3/cms-core
Introduced in: 9.0.0Fixed in: 9.5.4
Fixcomposer require typo3/cms-core:^9.5.4
Packagist/typo3/cms
Introduced in: 8.0.0Fixed in: 8.7.23
Fixcomposer require typo3/cms:^8.7.23
Packagist/typo3/cms
Introduced in: 9.0.0Fixed in: 9.5.4
Fixcomposer require typo3/cms:^9.5.4
RubyGems/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixbundle update bootstrap
Packagist/twbs/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixcomposer require twbs/bootstrap:^4.1.2
NuGet/bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fixdotnet add package bootstrap --version 4.1.2
NuGet/bootstrap.sass
Introduced in: 4.0.0Fixed in: 4.1.2
Fixdotnet add package bootstrap.sass --version 4.1.2
Maven/org.webjars:bootstrap
Introduced in: 4.0.0Fixed in: 4.1.2
Fix# pom.xml: bump <version>4.1.2</version> for org.webjars:bootstrap

References