Описание
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
A vulnerability was found in bootstrap associated with the data-loading-text attribute within the button plugin. This vulnerability allows malicious JavaScript code to be injected into the attribute, which is then executed when the button's loading state is triggered.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | bootstrap | Fix deferred | ||
| Red Hat Build of Keycloak | bootstrap | Not affected | ||
| Red Hat Ceph Storage 4 | ceph | Out of support scope | ||
| Red Hat Ceph Storage 5 | ceph | Out of support scope | ||
| Red Hat Ceph Storage 6 | ceph | Affected | ||
| Red Hat Ceph Storage 7 | ceph | Affected | ||
| Red Hat Certification for Red Hat Enterprise Linux 7 | redhat-certification | Affected | ||
| Red Hat Enterprise Linux 10 | ceph | Fix deferred | ||
| Red Hat Enterprise Linux 7 | firefox | Affected | ||
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
A security vulnerability has been discovered in bootstrap that could e ...
Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes
EPSS
6.4 Medium
CVSS3