GHSA-wh77-3x4m-4q9g

Suggest an improvement
Source
https://github.com/advisories/GHSA-wh77-3x4m-4q9g
Import Source
https://github.com/github/advisory-database/blob/main/GHSA-wh77-3x4m-4q9g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wh77-3x4m-4q9g
Withdrawn
2023-03-14T07:01:09Z
Published
2019-02-22T20:54:27Z
Modified
2023-03-14T07:01:09Z
Summary
Moderate severity vulnerability that affects bootstrap and bootstrap-sass
Details

In Bootstrap 4 before 4.3.1 and Bootstrap 3 before 3.4.1, XSS is possible in the tooltip or popover data-template attribute. For more information, see: https://blog.getbootstrap.com/2019/02/13/bootstrap-4-3-1-and-3-4-1/

References

Affected packages

npm / bootstrap-sass

Package

Name
bootstrap-sass
View open source insights on deps.dev
Purl
pkg:npm/bootstrap-sass

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.4.1

Database specific

cvss
{
    "score":  0,
    "vectorString":  null
}
cwes
[]
ghsa
"https://github.com/advisories/GHSA-wh77-3x4m-4q9g"
source
"https://github.com/github/advisory-database/blob/main/GHSA-wh77-3x4m-4q9g.json"

npm / bootstrap

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.4.1
Introduced
4.0.0
Fixed
4.3.1

Database specific

cvss
{
    "score":  0,
    "vectorString":  null
}
cwes
[]
ghsa
"https://github.com/advisories/GHSA-wh77-3x4m-4q9g"
source
"https://github.com/github/advisory-database/blob/main/GHSA-wh77-3x4m-4q9g.json"