Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-6485

Опубликовано: 11 июл. 2024
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

A vulnerability was found in bootstrap associated with the data-loading-text attribute within the button plugin. This vulnerability allows malicious JavaScript code to be injected into the attribute, which is then executed when the button's loading state is triggered.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7bootstrapFix deferred
Red Hat Build of KeycloakbootstrapNot affected
Red Hat Ceph Storage 4cephOut of support scope
Red Hat Ceph Storage 5cephOut of support scope
Red Hat Ceph Storage 6cephNot affected
Red Hat Ceph Storage 7cephNot affected
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certificationAffected
Red Hat Enterprise Linux 10cephFix deferred
Red Hat Enterprise Linux 7firefoxAffected
Red Hat Enterprise Linux 8389-ds:1.4/389-ds-baseNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2297388bootstrap: Cross-Site Scripting via button plugin on bootstrap

EPSS

Процентиль: 40%
0.00494
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
около 2 лет назад

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

CVSS3: 6.4
nvd
около 2 лет назад

A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

CVSS3: 6.4
msrc
9 месяцев назад

XSS in Bootstrap button component

CVSS3: 6.4
debian
около 2 лет назад

A security vulnerability has been discovered in bootstrap that could e ...

CVSS3: 6.4
github
около 2 лет назад

Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes

EPSS

Процентиль: 40%
0.00494
Низкий

6.4 Medium

CVSS3

Уязвимость CVE-2024-6485