RHSA-2020:5571MediumCVSS 6.1
Red Hat Security Advisory: python-XStatic-Bootstrap-SCSS security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2016-10735 — bootstrap: XSS in the data-target attribute CVE-2018-14042 — bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip CVE-2018-20676 — bootstrap: XSS in the tooltip data-viewport attribute CVE-2018-20677 — bootstrap: XSS in the affix configuration target property CVE-2019-8331 — bootstrap: XSS in the tooltip or popover data-template attribute
🎯 Affected products8
- Red Hat OpenStack Platform 13.0
- Red Hat OpenStack Platform 13.0 for RHEL 7.6 EUS Server
- python-XStatic-Bootstrap-SCSS-0:3.4.1.0-1.el7ost.noarch as a component of Red Hat OpenStack Platform 13.0
- python-XStatic-Bootstrap-SCSS-0:3.4.1.0-1.el7ost.noarch as a component of Red Hat OpenStack Platform 13.0 for RHEL 7.6 EUS Server
- python-XStatic-Bootstrap-SCSS-0:3.4.1.0-1.el7ost.src as a component of Red Hat OpenStack Platform 13.0
- python-XStatic-Bootstrap-SCSS-0:3.4.1.0-1.el7ost.src as a component of Red Hat OpenStack Platform 13.0 for RHEL 7.6 EUS Server
- xstatic-bootstrap-scss-common-0:3.4.1.0-1.el7ost.noarch as a component of Red Hat OpenStack Platform 13.0
- xstatic-bootstrap-scss-common-0:3.4.1.0-1.el7ost.noarch as a component of Red Hat OpenStack Platform 13.0 for RHEL 7.6 EUS Server
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:5571
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1601617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668082
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668097
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1686454
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_5571.json