Описание
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
Отчет
Red Hat Satellite 6.2 and newer versions don't use the bootstrap library, hence are not affected by this flaw. Red Hat CloudForms 4.6 and newer versions include the vulnerable component, but there is no risk of exploitation, since there is no possible vector to access the vulnerability. Older Red Hat CloudForms versions don't use the vulnerable component at all. Red Hat Enterprise Satellite 5 is now in Maintenance Support 2 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Satellite 5 Life Cycle: https://access.redhat.com/support/policy/updates/satellite.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
CloudForms Management Engine 5 | cfme-gemset | Not affected | ||
Red Hat 3scale API Management Platform 2 | bootstrap | Not affected | ||
Red Hat Decision Manager 7 | bootstrap | Will not fix | ||
Red Hat Enterprise Linux 7 | pki-core | Will not fix | ||
Red Hat OpenStack Platform 10 (Newton) | python-XStatic-Bootstrap-SCSS | Will not fix | ||
Red Hat OpenStack Platform 12 (Pike) | python-XStatic-Bootstrap-SCSS | Affected | ||
Red Hat OpenStack Platform 13 (Queens) | python-XStatic-Bootstrap-SCSS | Will not fix | ||
Red Hat OpenStack Platform 14 (Rocky) | python-XStatic-Bootstrap-SCSS | Affected | ||
Red Hat OpenStack Platform 8 (Liberty) | python-XStatic-Bootstrap-SCSS | Will not fix | ||
Red Hat OpenStack Platform 9 (Mitaka) | python-XStatic-Bootstrap-SCSS | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent ...
Bootstrap vulnerable to Cross-Site Scripting (XSS)
Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update
EPSS
6.1 Medium
CVSS3