Описание
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
A cross-site scripting vulnerability was discovered in bootstrap. If an attacker could control the data given to tooltip or popover, they could inject HTML or Javascript into the rendered page when tooltip or popover events fired.
Отчет
Red Hat CloudForms 4.6 and newer versions include the vulnerable component, but there is no risk of exploitation since there is no possible vector to access the vulnerability. Older Red Hat CloudForms versions don't use the vulnerable component at all.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
CloudForms Management Engine 5 | bootstrap-sass | Not affected | ||
Red Hat 3scale API Management Platform 2 | bootstrap | Not affected | ||
Red Hat Decision Manager 7 | bootstrap | Will not fix | ||
Red Hat Enterprise Linux 7 | pki-core | Will not fix | ||
Red Hat JBoss Enterprise Web Server 2 | bootstrap | Out of support scope | ||
Red Hat OpenShift Application Runtimes | bootstrap | Affected | ||
Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Out of support scope | ||
Red Hat OpenStack Platform 10 (Newton) | python-XStatic-Bootstrap-SCSS | Will not fix | ||
Red Hat OpenStack Platform 14 (Rocky) | python-XStatic-Bootstrap-SCSS | Affected | ||
Red Hat OpenStack Platform 15 (Stein) | python-XStatic-Bootstrap-SCSS | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in t ...
Уязвимость компонентов tooltip и popover набора инструментов для создания сайтов и веб-приложений Bootstrap, позволяющая нарушителю осуществлять межсайтовые сценарные атаки
EPSS
6.1 Medium
CVSS3