Reflected cross-site scripting (XSS) In twitter-bootstrap3
Description
Bootstrap Vulnerable to Cross-Site Scripting
Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
Recommendation
For bootstrap 4.x upgrade to 4.3.1 or later.
For bootstrap 3.x upgrade to 3.4.1 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 3.4.1+dfsg-1 | ||
debian 14 | 3.4.1+dfsg-1 | ||
rubygems | 5.3.0 | ||
npm | 3.4.1, 3.4.1 | ||
nuget | 4.3.1 | ||
nuget | 3.4.1 | ||
packagist | 3.4.1, 4.3.1 | ||
npm | 4.3.1, 4.3.1, 3.4.1, 4.3.1, 3.4.1 | ||
maven | 3.4.1, 4.3.1 | ||
nuget | 3.4.1, 4.3.1 |
1-10 of 21
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33. 34. 35. 36. 37. 38. 39.