Описание
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| twitter-bootstrap | removed | package | ||
| twitter-bootstrap | no-dsa | stretch | package | |
| twitter-bootstrap | no-dsa | jessie | package | |
| twitter-bootstrap3 | fixed | 3.4.0+dfsg-1 | package | |
| twitter-bootstrap3 | fixed | 3.3.7+dfsg-2+deb9u1 | stretch | package |
| twitter-bootstrap3 | no-dsa | jessie | package |
Примечания
https://github.com/twbs/bootstrap/issues/27045
https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906
https://github.com/twbs/bootstrap/issues/27915#issuecomment-452196628
https://github.com/twbs/bootstrap/pull/27047
https://github.com/twbs/bootstrap/commit/2a5ba23ce8f041f3548317acc992ed8a736b609d (v3.4.0)
EPSS
Связанные уязвимости
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
EPSS