RubySec

Providing security resources for the Ruby community

CVE-2018-14040 (bootstrap-sass): Bootstrap vulnerable to Cross-Site Scripting (XSS)

ADVISORIES

GEM

bootstrap-sass

SEVERITY

CVSS v3.x: 6.1 (Medium)

CVSS v2.0: 4.3 (Medium)

UNAFFECTED VERSIONS

  • < 2.3.0

PATCHED VERSIONS

  • ~> 3.4.0
  • >= 4.1.2

DESCRIPTION

In Bootstrap starting in version 2.3.0 and prior to 3.4.0, as well as 4.x before 4.1.2, XSS is possible in the collapse data-parent attribute.

RELATED