-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Vulnerable Library - bootstrap-3.3.7.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.js
Path to vulnerable library: /docs/site/js/bootstrap-3.3.7.js
Found in HEAD commit: df5eee361322a43b3eb9023f603741629861c6c2
Vulnerabilities
| Vulnerability | Severity | Dependency | Type | Fixed in (bootstrap version) | Remediation Possible** | |
|---|---|---|---|---|---|---|
| CVE-2024-6485 | 6.4 | bootstrap-3.3.7.js | Direct | https://github.com/twbs/bootstrap.git - v4.0.0 | ❌ | |
| CVE-2019-8331 | 6.1 | bootstrap-3.3.7.js | Direct | org.webjars:bootstrap:3.4.1,bootstrap - 4.3.1,bootstrap-sass - 3.4.1,bootstrap-sass - 3.4.1,bootstrap - 3.4.1,bootstrap.sass - 4.3.1,org.webjars:bootstrap:4.3.1,bootstrap - 4.3.1,bootstrap.less - 3.4.1,bootstrap - 4.3.1,bootstrap - 3.4.1 | ❌ | |
| CVE-2018-20677 | 6.1 | bootstrap-3.3.7.js | Direct | bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,org.webjars:bootstrap:3.4.0,bootstrap-sass - 3.4.0,bootstrap-sass - 3.4.0 | ❌ | |
| CVE-2018-20676 | 6.1 | bootstrap-3.3.7.js | Direct | bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0 | ❌ | |
| CVE-2018-14042 | 6.1 | bootstrap-3.3.7.js | Direct | bootstrap - 3.4.0,4.1.2,bootstrap-sass - 3.4.0,bootstrap.sass - 4.1.2,bootstrap - 4.1.2,org.webjars:bootstrap:4.1.2,bootstrap - 4.1.2,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 4.1.2,org.webjars:bootstrap:3.4.0 | ❌ | |
| CVE-2018-14040 | 6.1 | bootstrap-3.3.7.js | Direct | bootstrap - 3.4.0,4.1.2,https://github.com/twbs/bootstrap.git - v4.1.2 | ❌ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2024-6485
Vulnerable Library - bootstrap-3.3.7.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.js
Path to vulnerable library: /docs/site/js/bootstrap-3.3.7.js
Dependency Hierarchy:
- ❌ bootstrap-3.3.7.js (Vulnerable Library)
Found in HEAD commit: df5eee361322a43b3eb9023f603741629861c6c2
Found in base branch: master
Vulnerability Details
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
Publish Date: 2024-07-11
URL: CVE-2024-6485
CVSS 3 Score Details (6.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: Low
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Origin: https://getbootstrap.com/docs/3.3/javascript/#buttons
Release Date: 2024-07-11
Fix Resolution: https://github.com/twbs/bootstrap.git - v4.0.0
Step up your Open Source Security Game with Mend here
CVE-2019-8331
Vulnerable Library - bootstrap-3.3.7.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.js
Path to vulnerable library: /docs/site/js/bootstrap-3.3.7.js
Dependency Hierarchy:
- ❌ bootstrap-3.3.7.js (Vulnerable Library)
Found in HEAD commit: df5eee361322a43b3eb9023f603741629861c6c2
Found in base branch: master
Vulnerability Details
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Publish Date: 2019-02-20
URL: CVE-2019-8331
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-9v3m-8fp8-mj99
Release Date: 2019-02-20
Fix Resolution: org.webjars:bootstrap:3.4.1,bootstrap - 4.3.1,bootstrap-sass - 3.4.1,bootstrap-sass - 3.4.1,bootstrap - 3.4.1,bootstrap.sass - 4.3.1,org.webjars:bootstrap:4.3.1,bootstrap - 4.3.1,bootstrap.less - 3.4.1,bootstrap - 4.3.1,bootstrap - 3.4.1
Step up your Open Source Security Game with Mend here
CVE-2018-20677
Vulnerable Library - bootstrap-3.3.7.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.js
Path to vulnerable library: /docs/site/js/bootstrap-3.3.7.js
Dependency Hierarchy:
- ❌ bootstrap-3.3.7.js (Vulnerable Library)
Found in HEAD commit: df5eee361322a43b3eb9023f603741629861c6c2
Found in base branch: master
Vulnerability Details
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
Publish Date: 2019-01-09
URL: CVE-2018-20677
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-20677
Release Date: 2019-01-09
Fix Resolution: bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,org.webjars:bootstrap:3.4.0,bootstrap-sass - 3.4.0,bootstrap-sass - 3.4.0
Step up your Open Source Security Game with Mend here
CVE-2018-20676
Vulnerable Library - bootstrap-3.3.7.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.js
Path to vulnerable library: /docs/site/js/bootstrap-3.3.7.js
Dependency Hierarchy:
- ❌ bootstrap-3.3.7.js (Vulnerable Library)
Found in HEAD commit: df5eee361322a43b3eb9023f603741629861c6c2
Found in base branch: master
Vulnerability Details
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
Publish Date: 2019-01-09
URL: CVE-2018-20676
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20676
Release Date: 2019-01-09
Fix Resolution: bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0
Step up your Open Source Security Game with Mend here
CVE-2018-14042
Vulnerable Library - bootstrap-3.3.7.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.js
Path to vulnerable library: /docs/site/js/bootstrap-3.3.7.js
Dependency Hierarchy:
- ❌ bootstrap-3.3.7.js (Vulnerable Library)
Found in HEAD commit: df5eee361322a43b3eb9023f603741629861c6c2
Found in base branch: master
Vulnerability Details
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
Publish Date: 2018-07-13
URL: CVE-2018-14042
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-14042
Release Date: 2018-07-13
Fix Resolution: bootstrap - 3.4.0,4.1.2,bootstrap-sass - 3.4.0,bootstrap.sass - 4.1.2,bootstrap - 4.1.2,org.webjars:bootstrap:4.1.2,bootstrap - 4.1.2,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 4.1.2,org.webjars:bootstrap:3.4.0
Step up your Open Source Security Game with Mend here
CVE-2018-14040
Vulnerable Library - bootstrap-3.3.7.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.js
Path to vulnerable library: /docs/site/js/bootstrap-3.3.7.js
Dependency Hierarchy:
- ❌ bootstrap-3.3.7.js (Vulnerable Library)
Found in HEAD commit: df5eee361322a43b3eb9023f603741629861c6c2
Found in base branch: master
Vulnerability Details
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
Publish Date: 2018-07-13
URL: CVE-2018-14040
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-14040
Release Date: 2018-07-13
Fix Resolution: bootstrap - 3.4.0,4.1.2,https://github.com/twbs/bootstrap.git - v4.1.2
Step up your Open Source Security Game with Mend here