Impact: Moderate Public Date: 2019-02-11 CWE: CWE-79 Bugzilla: 1686454: CVE-2019-8331 bootstrap: XSS in the tooltip or popover data-template attribute In Bootstrap before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2019-8331 from the MITRE CVE dictionary dictionary and NIST NVD.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
CVSS3 Base Score | 6.1 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | Required |
Scope | Changed |
Confidentiality | Low |
Integrity Impact | Low |
Availability Impact | None |
Platform | Package | State |
---|---|---|
Red Hat Virtualization 4 | ovirt-js-dependencies | Under investigation |
Red Hat Satellite 5 | bootstrap | Under investigation |
Red Hat OpenStack Platform 9.0 | python-XStatic-Bootstrap-SCSS | Under investigation |
Red Hat OpenStack Platform 8.0 (Liberty) | python-XStatic-Bootstrap-SCSS | Under investigation |
Red Hat OpenStack Platform 14 | python-XStatic-Bootstrap-SCSS | Under investigation |
Red Hat OpenStack Platform 13.0 (Queens) | python-XStatic-Bootstrap-SCSS | Under investigation |
Red Hat OpenStack Platform 10 | python-XStatic-Bootstrap-SCSS | Under investigation |
Red Hat OpenShift Application Runtimes 1.0 | swarm | Under investigation |
Red Hat JBoss EWS 2 | bootstrap | Under investigation |
Red Hat Gluster Storage 3 | bootstrap | Under investigation |