Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14041

Опубликовано: 29 мая 2018
Источник: redhat
CVSS3: 6.1

Описание

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting, caused by improper validation of user-supplied input by the data-target property of scrollspy. This flaw allows a remote attacker to execute a script in a victim's Web browser within the security context of the hosting Web site, which can lead to stealing the victim's cookie-based authentication credentials.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-gemsetNot affected
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected
Red Hat Ceph Storage 4cephAffected
Red Hat Ceph Storage 5cephAffected
Red Hat Decision Manager 7bootstrapNot affected
Red Hat Discovery 1discovery-server-containerNot affected
Red Hat Enterprise Linux 7ipaNot affected
Red Hat Enterprise Linux 7pki-coreNot affected
Red Hat Enterprise Linux 8389-ds:1.4/389-ds-baseUnder investigation
Red Hat Enterprise Linux 8cockpitUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1601616bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 7 лет назад

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

CVSS3: 6.1
nvd
больше 7 лет назад

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

CVSS3: 6.1
debian
больше 7 лет назад

In Bootstrap before 4.1.2, XSS is possible in the data-target property ...

CVSS3: 6.1
github
больше 7 лет назад

Bootstrap Cross-site Scripting vulnerability

CVSS3: 6.1
fstec
больше 7 лет назад

Уязвимость плагина ScrollSpy набора инструментов для создания сайтов и веб-приложений Bootstrap, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

6.1 Medium

CVSS3