In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
Loading...
Loading...
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
January 9, 2019
November 21, 2024
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bootstrap | — | 3.4.0 | — |
| bootstrap-sass | — | 3.4.0 | — |
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bootstrap | — | 3.4.0 | — |
| bootstrap-sass | 1.2.0 ... 3.3.7 (57 versions) | 3.4.0 | — |
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.webjars:bootstrap | 1.3.0 ... 3.3.7-1 (33 versions) | 3.4.0 | — |
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bootstrap | 1.0.0 ... 3.3.7 (19 versions) | 3.4.0 | — |
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| twbs/bootstrap | v2.2.2 ... v3.3.7 (20 versions) | 3.4.0 | — |
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2018-20676
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.