bootstrap-sass
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting bootstrap-sasspage 1 of 1
- CVE-2016-10735MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02019-01-09
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
- CVE-2018-14042MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02018-07-13
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
- CVE-2018-20676MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02019-01-09
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
- CVE-2018-20677MEDIUMCVSS 6.1EG 6.1fixed in 3.4.02019-01-09
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
- CVE-2019-8331MEDIUMCVSS 6.1EG 6.1fixed in 3.4.12019-02-20
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Check whether bootstrap-sass is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for bootstrap-sass CVEs against the assets you own.
Book a Demo →