Vulnerability GHSA-9v3m-8fp8-mj99
Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 years ago
February 22, 2019 at 08:54 PM UTC
Bootstrap Vulnerable to Cross-Site Scripting
3.1.1 - 3.4.0 and 4.0.0 - 4.3.0
3.1.1 - 3.4.0 and 4.0.0 - 4.3.0
Summary
Bootstrap Vulnerable to Cross-Site Scripting
Details
Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
Recommendation
For bootstrap 4.x upgrade to 4.3.1 or later. For bootstrap 3.x upgrade to 3.4.1 or later.
References
- ADVISORY — nvd.nist.gov
- WEB — github.com
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — seclists.org
- WEB — support.f5.com
- WEB — support.f5.com
- WEB — support.f5.com
- WEB — web.archive.org
- WEB — www.oracle.com
- WEB — www.tenable.com
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — blog.getbootstrap.com
- WEB — cve.mitre.org
- ADVISORY — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- PACKAGE — github.com
- WEB — github.com
- WEB — github.com
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — lists.apache.org
- WEB — packetstormsecurity.com
- WEB — seclists.org
- WEB — seclists.org
- WEB — seclists.org
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
1 year ago
Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components
3.4.1 GHSA-q58r-hwc8-rm9j
3.4.1 GHSA-q58r-hwc8-rm9j
Medium Risk
2 years ago
Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes
3.1.1 - 3.4.1 GHSA-vxmc-5x29-h64v
3.1.1 - 3.4.1 GHSA-vxmc-5x29-h64v
Medium Risk
3 years ago
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails
0.0.3 - 2.0 and 2.0.0 - 2.0.1 and 2.0.1.0 - 2.2.8 GHSA-vpqv-mqvc-pcx2
0.0.3 - 2.0 and 2.0.0 - 2.0.1 and 2.0.1.0 - 2.2.8 GHSA-vpqv-mqvc-pcx2
Medium Risk
4 years ago
Bootstrap vulnerable to Cross-Site Scripting (XSS)
2.3.1 - 2.3.2 and 3.1.0 - 3.2.0 and 3.3.7 - 4.1.1 GHSA-3wqf-4x89-9g79
2.3.1 - 2.3.2 and 3.1.0 - 3.2.0 and 3.3.7 - 4.1.1 GHSA-3wqf-4x89-9g79
Medium Risk
4 years ago
Bootstrap vulnerable to Cross-Site Scripting (XSS)
2.3.1 - 2.3.2 and 3.1.0 - 3.2.0 and 3.3.7 - 4.1.1 GHSA-3wqf-4x89-9g79
2.3.1 - 2.3.2 and 3.1.0 - 3.2.0 and 3.3.7 - 4.1.1 GHSA-3wqf-4x89-9g79
Impacted packages
Timeline
Published
7 years ago
February 22, 2019 at 08:54 PM UTC
Fixed (3.4.1)
7 years ago
February 13, 2019 at 03:55 PM UTC
Fixed (3.4.1)
7 years ago
February 13, 2019 at 04:00 PM UTC
Fixed (4.3.1)
7 years ago
February 13, 2019 at 04:01 PM UTC
Fixed (4.3.1)
7 years ago
February 13, 2019 at 04:03 PM UTC
Fixed (4.3.1)
7 years ago
February 13, 2019 at 06:53 PM UTC
Fixed (3.4.1)
7 years ago
February 13, 2019 at 07:00 PM UTC
Fixed (3.4.1)
7 years ago
February 13, 2019 at 07:00 PM UTC
Fixed (3.4.1)
7 years ago
February 13, 2019 at 09:30 PM UTC
Fixed (3.4.1)
7 years ago
February 13, 2019 at 09:31 PM UTC
Fixed (4.3.1)
7 years ago
February 13, 2019 at 09:33 PM UTC
Fixed (4.3.1)
7 years ago
February 13, 2019 at 09:33 PM UTC
Fixed (5.3.0)
7 months ago
February 18, 2026 at 06:28 PM UTC
Fixed (3.4.1)
Unknown
Unknown
Fixed (4.3.1)
Unknown
Unknown
Last Modified
29 days ago
September 10, 2026 at 03:47 AM UTC