Описание
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
Отчет
Red Hat Enterprise Satellite 5 is now in Maintenance Support 2 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Satellite 5 Life Cycle: https://access.redhat.com/support/policy/updates/satellite. Red Hat Virtualization 4.2 EUS contains the affected version of bootstrap in the packages ovirt-js-dependencies and ovirt-engine-dashboard. These packages are deprecated in Red Hat Virtualization 4.3.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | pki-core | Will not fix | ||
Red Hat JBoss Enterprise Web Server 2 | bootstrap | Affected | ||
Red Hat OpenStack Platform 10 (Newton) | python-XStatic-Bootstrap-SCSS | Affected | ||
Red Hat OpenStack Platform 14 (Rocky) | python-XStatic-Bootstrap-SCSS | Affected | ||
Red Hat OpenStack Platform 15 (Stein) | python-XStatic-Bootstrap-SCSS | Affected | ||
Red Hat OpenStack Platform 8 (Liberty) | python-XStatic-Bootstrap-SCSS | Affected | ||
Red Hat OpenStack Platform 9 (Mitaka) | python-XStatic-Bootstrap-SCSS | Affected | ||
Red Hat Quay 3 | quay | Not affected | ||
Red Hat Quay 3 | quay/quay-rhel8 | Not affected | ||
Red Hat Satellite 5 | bootstrap | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is ...
Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update
EPSS
6.1 Medium
CVSS3