Vulnerability GHSA-3wqf-4x89-9g79
Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
May 13, 2022 at 01:07 AM UTC
Bootstrap vulnerable to Cross-Site Scripting (XSS)
3.1.1 - 3.3.7 and 4.0.0 - 4.1.1
3.1.1 - 3.3.7 and 4.0.0 - 4.1.1
Summary
Bootstrap vulnerable to Cross-Site Scripting (XSS)
Details
In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute.
References
- ADVISORY — nvd.nist.gov
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — www.tenable.com
- WEB — www.oracle.com
- WEB — seclists.org
- WEB — lists.debian.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — blog.getbootstrap.com
- WEB — packetstormsecurity.com
- WEB — packetstormsecurity.com
- WEB — seclists.org
- WEB — seclists.org
- WEB — seclists.org
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
1 year ago
Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components
3.4.1 GHSA-q58r-hwc8-rm9j
3.4.1 GHSA-q58r-hwc8-rm9j
Medium Risk
2 years ago
Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes
3.1.1 - 3.4.1 GHSA-vxmc-5x29-h64v
3.1.1 - 3.4.1 GHSA-vxmc-5x29-h64v
Critical
7 years ago
Bootstrap-sass contains code execution backdoor
==3.2.0.3 GHSA-vqqv-v9m2-48p2
==3.2.0.3 GHSA-vqqv-v9m2-48p2
Medium Risk
7 years ago
Bootstrap Vulnerable to Cross-Site Scripting
3.1.0 - 3.2.0 and 3.3.7 - 4.0.0 and 4.2.1 GHSA-9v3m-8fp8-mj99
3.1.0 - 3.2.0 and 3.3.7 - 4.0.0 and 4.2.1 GHSA-9v3m-8fp8-mj99
Medium Risk
7 years ago
Bootstrap Vulnerable to Cross-Site Scripting
3.1.0 - 3.2.0 and 3.3.7 - 4.0.0 and 4.2.1 GHSA-9v3m-8fp8-mj99
3.1.0 - 3.2.0 and 3.3.7 - 4.0.0 and 4.2.1 GHSA-9v3m-8fp8-mj99
Impacted packages
Timeline
Published
4 years ago
May 13, 2022 at 01:07 AM UTC
Fixed (4.1.2)
8 years ago
July 12, 2018 at 04:27 PM UTC
Fixed (4.1.2)
8 years ago
July 12, 2018 at 04:38 PM UTC
Fixed (4.1.2)
8 years ago
July 19, 2018 at 01:05 PM UTC
Fixed (4.1.2)
8 years ago
July 19, 2018 at 01:06 PM UTC
Fixed (4.1.2)
8 years ago
July 23, 2018 at 12:10 PM UTC
Fixed (3.4.0)
7 years ago
December 13, 2018 at 11:45 PM UTC
Fixed (3.4.0)
7 years ago
December 13, 2018 at 11:50 PM UTC
Fixed (3.4.0)
7 years ago
December 14, 2018 at 12:37 PM UTC
Fixed (3.4.0)
7 years ago
December 16, 2018 at 04:18 AM UTC
Fixed (4.1.2)
Unknown
Unknown
Fixed (3.4.0)
Unknown
Unknown
Last Modified
29 days ago
September 10, 2026 at 03:49 AM UTC