Skip to content

bootstrap-3.2.0.min.js: 6 vulnerabilities (highest severity is: 6.1) [main] #7

@renovate

Description

@renovate
📂 Vulnerable Library - bootstrap-3.2.0.min.js

The most popular front-end framework for developing responsive, mobile first projects on the web.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js

Path to vulnerable library: /Web/Scripts/bootstrap.min.js

Findings

Finding Severity 🎯 CVSS Exploit Maturity EPSS Library Type Fixed in Remediation Available
CVE-2016-10735 🟠 Medium 6.1 Not Defined 2.6000001% bootstrap-3.2.0.min.js Direct bootstrap - 3.4.0, 4.0.0-beta.2
CVE-2018-14040 🟠 Medium 6.1 Not Defined 3.3% bootstrap-3.2.0.min.js Direct bootstrap - 3.4.0,4.1.2
CVE-2018-14042 🟠 Medium 6.1 Not Defined 3.5% bootstrap-3.2.0.min.js Direct bootstrap - 3.4.0,4.1.2
CVE-2018-20676 🟠 Medium 6.1 Not Defined 2.7% bootstrap-3.2.0.min.js Direct bootstrap - 3.4.0
CVE-2018-20677 🟠 Medium 6.1 Not Defined 9.4% bootstrap-3.2.0.min.js Direct bootstrap - 3.4.0
CVE-2019-8331 🟠 Medium 6.1 Not Defined 2.5% bootstrap-3.2.0.min.js Direct bootstrap - 3.4.1,4.3.1;bootstrap-sass - 3.4.1,4.3.1

Details

🟠CVE-2016-10735

Vulnerable Library - bootstrap-3.2.0.min.js

The most popular front-end framework for developing responsive, mobile first projects on the web.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js

Path to vulnerable library: /Web/Scripts/bootstrap.min.js

Dependency Hierarchy:

  • bootstrap-3.2.0.min.js (Vulnerable Library)

Vulnerability Details

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041. Converted from WS-2018-0021, on 2022-11-08.

Publish Date: Jan 09, 2019 05:00 AM

URL: CVE-2016-10735

Threat Assessment

Exploit Maturity:Not Defined

EPSS:2.6000001%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10735

Release Date: Jan 09, 2019 05:00 AM

Fix Resolution : bootstrap - 3.4.0, 4.0.0-beta.2

🟠CVE-2018-14040

Vulnerable Library - bootstrap-3.2.0.min.js

The most popular front-end framework for developing responsive, mobile first projects on the web.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js

Path to vulnerable library: /Web/Scripts/bootstrap.min.js

Dependency Hierarchy:

  • bootstrap-3.2.0.min.js (Vulnerable Library)

Vulnerability Details

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

Publish Date: Jul 13, 2018 02:00 PM

URL: CVE-2018-14040

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.3%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-14040

Release Date: Jul 13, 2018 02:00 PM

Fix Resolution : bootstrap - 3.4.0,4.1.2

🟠CVE-2018-14042

Vulnerable Library - bootstrap-3.2.0.min.js

The most popular front-end framework for developing responsive, mobile first projects on the web.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js

Path to vulnerable library: /Web/Scripts/bootstrap.min.js

Dependency Hierarchy:

  • bootstrap-3.2.0.min.js (Vulnerable Library)

Vulnerability Details

In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

Publish Date: Jul 13, 2018 02:00 PM

URL: CVE-2018-14042

Threat Assessment

Exploit Maturity:Not Defined

EPSS:3.5%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-14042

Release Date: Jul 13, 2018 02:00 PM

Fix Resolution : bootstrap - 3.4.0,4.1.2

🟠CVE-2018-20676

Vulnerable Library - bootstrap-3.2.0.min.js

The most popular front-end framework for developing responsive, mobile first projects on the web.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js

Path to vulnerable library: /Web/Scripts/bootstrap.min.js

Dependency Hierarchy:

  • bootstrap-3.2.0.min.js (Vulnerable Library)

Vulnerability Details

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

Publish Date: Jan 09, 2019 05:00 AM

URL: CVE-2018-20676

Threat Assessment

Exploit Maturity:Not Defined

EPSS:2.7%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20676

Release Date: Jan 09, 2019 05:00 AM

Fix Resolution : bootstrap - 3.4.0

🟠CVE-2018-20677

Vulnerable Library - bootstrap-3.2.0.min.js

The most popular front-end framework for developing responsive, mobile first projects on the web.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js

Path to vulnerable library: /Web/Scripts/bootstrap.min.js

Dependency Hierarchy:

  • bootstrap-3.2.0.min.js (Vulnerable Library)

Vulnerability Details

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

Publish Date: Jan 09, 2019 05:00 AM

URL: CVE-2018-20677

Threat Assessment

Exploit Maturity:Not Defined

EPSS:9.4%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-20677

Release Date: Jan 09, 2019 05:00 AM

Fix Resolution : bootstrap - 3.4.0

🟠CVE-2019-8331

Vulnerable Library - bootstrap-3.2.0.min.js

The most popular front-end framework for developing responsive, mobile first projects on the web.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js

Path to vulnerable library: /Web/Scripts/bootstrap.min.js

Dependency Hierarchy:

  • bootstrap-3.2.0.min.js (Vulnerable Library)

Vulnerability Details

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

Publish Date: Feb 20, 2019 04:00 PM

URL: CVE-2019-8331

Threat Assessment

Exploit Maturity:Not Defined

EPSS:2.5%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: twbs/bootstrap#28236

Release Date: Feb 20, 2019 04:00 PM

Fix Resolution : bootstrap - 3.4.1,4.3.1;bootstrap-sass - 3.4.1,4.3.1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions