Описание
bootstrap Cross-site Scripting vulnerability
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-20677
- https://github.com/twbs/bootstrap/issues/27915#issuecomment-452196628
- https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906
- https://github.com/twbs/bootstrap/issues/27045
- https://github.com/twbs/bootstrap/pull/27047
- https://github.com/twbs/bootstrap/commit/2a5ba23ce8f041f3548317acc992ed8a736b609d
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e@%3Cdev.superset.apache.org%3E
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bootstrap/CVE-2018-20677.yml
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bootstrap-sass/CVE-2018-20677.yml
- https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0
- https://access.redhat.com/errata/RHSA-2020:0133
- https://access.redhat.com/errata/RHSA-2020:0132
- https://access.redhat.com/errata/RHSA-2019:3023
- https://access.redhat.com/errata/RHSA-2019:1456
- https://access.redhat.com/errata/RHBA-2019:1570
- https://access.redhat.com/errata/RHBA-2019:1076
Пакеты
bootstrap
< 3.4.0
3.4.0
bootstrap-sass
< 3.4.0
3.4.0
twbs/bootstrap
< 3.4.0
3.4.0
org.webjars:bootstrap
< 3.4.0
3.4.0
bootstrap
< 3.4.0
3.4.0
bootstrap-sass
< 3.4.0
3.4.0
bootstrap
< 3.4.0
3.4.0
Связанные уязвимости
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
In Bootstrap before 3.4.0, XSS is possible in the affix configuration ...
Уязвимость плагина affix набора инструментов для создания сайтов и веб-приложений Bootstrap, позволяющая нарушителю осуществлять межсайтовые сценарные атаки