Reflected cross-site scripting (XSS) In bootstrap-sass
Description
Bootstrap Vulnerable to Cross-Site Scripting
Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
Recommendation
For bootstrap 4.x upgrade to 4.3.1 or later.
For bootstrap 3.x upgrade to 3.4.1 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 3.4.1+dfsg-1 | ||
rubygems | 3.4.1 | ||
npm | 3.4.1 | ||
debian 13 | 3.4.1+dfsg-1 | ||
rubygems | 5.3.0 | ||
nuget | 4.3.1 | ||
nuget | 3.4.1 | ||
packagist | 3.4.1, 4.3.1 | ||
npm | 4.3.1, 3.4.1 | ||
maven | 3.4.1, 4.3.1 |
1-10 of 21
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33. 34. 35. 36. 37. 38. 39.