Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20921

Опубликовано: 14 фев. 2019
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.

Отчет

In OpenShift Service Mesh (OSSM) the openshift-service-mesh/kiali-rhel7 container (which installs the kiali rpm) is behind OpenShift OAuth authentication restricting access to the vulnerable bootstrap-select library to authenticated users only, therefore the impact is low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1kialiFix deferred
Red Hat OpenShift Container Platform 3.11openshift3/ose-consoleNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected
Red Hat Single Sign-On 7keycloak-themeWill not fix
Red Hat Virtualization 4ovirt-engineWill not fix
Red Hat Virtualization Engine 4.4ovirt-web-uiFixedRHSA-2021:116914.04.2021
Red Hat Virtualization Engine 4.4ovirt-engine-ui-extensionsFixedRHSA-2021:118614.04.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1882273nodejs-bootstrap-select: not escaping title values on <option> may lead to XSS

EPSS

Процентиль: 67%
0.00545
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.

CVSS3: 6.1
github
почти 5 лет назад

Cross-site scripting in bootstrap-select

EPSS

Процентиль: 67%
0.00545
Низкий

6.1 Medium

CVSS3