Skip to content

bootstrap-3.3.7.jar: 6 vulnerabilities (highest severity is: 6.1) [main] #19

@renovate

Description

@renovate
📂 Vulnerable Library - bootstrap-3.3.7.jar

WebJar for Bootstrap

Library home page: http://webjars.org

Path to dependency file: /pom.xml

Findings

Finding Severity 🎯 CVSS Exploit Maturity EPSS Library Type Fixed in Remediation Available Reachability
CVE-2016-10735 🟠 Medium 6.1 Not Defined 5.337% bootstrap-3.3.7.jar Direct bootstrap - 3.4.0, 4.0.0-beta.2
CVE-2018-14040 🟠 Medium 6.1 Not Defined 1.92% bootstrap-3.3.7.jar Direct bootstrap - 3.4.0,4.1.2,https://github.com/twbs/bootstrap.git - v4.1.2
CVE-2018-14042 🟠 Medium 6.1 Not Defined 2.281% bootstrap-3.3.7.jar Direct org.webjars:bootstrap:4.1.2,bootstrap - 4.1.2,org.webjars:bootstrap:3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,4.1.2,bootstrap - 4.1.2,bootstrap-sass - 3.4.0
CVE-2018-20676 🟠 Medium 6.1 Not Defined 5.541% bootstrap-3.3.7.jar Direct bootstrap - 3.4.0,bootstrap-sass - 3.4.0,https://github.com/twbs/bootstrap.git - v3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0
CVE-2018-20677 🟠 Medium 6.1 Not Defined 9.805% bootstrap-3.3.7.jar Direct org.webjars:bootstrap:3.4.0,bootstrap-sass - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0
CVE-2019-8331 🟠 Medium 6.1 Not Defined 1.668% bootstrap-3.3.7.jar Direct bootstrap-sass - 3.4.1,bootstrap - 4.3.1,org.webjars:bootstrap:3.4.1,org.webjars:bootstrap:4.3.1,bootstrap - 4.3.1,bootstrap.less - 3.4.1,bootstrap - 4.3.1,bootstrap.sass - 4.3.1,bootstrap - 3.4.1,bootstrap-sass - 3.4.1,bootstrap - 3.4.1

Details

🟠CVE-2016-10735

Vulnerable Library - bootstrap-3.3.7.jar

WebJar for Bootstrap

Library home page: http://webjars.org

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • bootstrap-3.3.7.jar (Vulnerable Library)

Vulnerability Details

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: Jan 09, 2019 05:00 AM

URL: CVE-2016-10735

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.337%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10735

Release Date: Jan 09, 2019 05:00 AM

Fix Resolution : bootstrap - 3.4.0, 4.0.0-beta.2

🟠CVE-2018-14040

Vulnerable Library - bootstrap-3.3.7.jar

WebJar for Bootstrap

Library home page: http://webjars.org

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • bootstrap-3.3.7.jar (Vulnerable Library)

Vulnerability Details

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

Publish Date: Jul 13, 2018 02:00 PM

URL: CVE-2018-14040

Threat Assessment

Exploit Maturity:Not Defined

EPSS:1.92%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2018-14040

Release Date: Jul 13, 2018 02:00 PM

Fix Resolution : bootstrap - 3.4.0,4.1.2,https://github.com/twbs/bootstrap.git - v4.1.2

🟠CVE-2018-14042

Vulnerable Library - bootstrap-3.3.7.jar

WebJar for Bootstrap

Library home page: http://webjars.org

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • bootstrap-3.3.7.jar (Vulnerable Library)

Vulnerability Details

In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

Publish Date: Jul 13, 2018 02:00 PM

URL: CVE-2018-14042

Threat Assessment

Exploit Maturity:Not Defined

EPSS:2.281%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: GHSA-7mvr-5x2g-wfc8

Release Date: Jul 13, 2018 02:00 PM

Fix Resolution : org.webjars:bootstrap:4.1.2,bootstrap - 4.1.2,org.webjars:bootstrap:3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,4.1.2,bootstrap - 4.1.2,bootstrap-sass - 3.4.0

🟠CVE-2018-20676

Vulnerable Library - bootstrap-3.3.7.jar

WebJar for Bootstrap

Library home page: http://webjars.org

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • bootstrap-3.3.7.jar (Vulnerable Library)

Vulnerability Details

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

Publish Date: Jan 09, 2019 05:00 AM

URL: CVE-2018-20676

Threat Assessment

Exploit Maturity:Not Defined

EPSS:5.541%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: GHSA-3mgp-fx93-9xv5

Release Date: Jan 09, 2019 05:00 AM

Fix Resolution : bootstrap - 3.4.0,bootstrap-sass - 3.4.0,https://github.com/twbs/bootstrap.git - v3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0

🟠CVE-2018-20677

Vulnerable Library - bootstrap-3.3.7.jar

WebJar for Bootstrap

Library home page: http://webjars.org

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • bootstrap-3.3.7.jar (Vulnerable Library)

Vulnerability Details

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

Publish Date: Jan 09, 2019 05:00 AM

URL: CVE-2018-20677

Threat Assessment

Exploit Maturity:Not Defined

EPSS:9.805%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: GHSA-ph58-4vrj-w6hr

Release Date: Jan 09, 2019 05:00 AM

Fix Resolution : org.webjars:bootstrap:3.4.0,bootstrap-sass - 3.4.0,bootstrap-sass - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0,bootstrap - 3.4.0

🟠CVE-2019-8331

Vulnerable Library - bootstrap-3.3.7.jar

WebJar for Bootstrap

Library home page: http://webjars.org

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • bootstrap-3.3.7.jar (Vulnerable Library)

Vulnerability Details

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

Publish Date: Feb 20, 2019 04:00 PM

URL: CVE-2019-8331

Threat Assessment

Exploit Maturity:Not Defined

EPSS:1.668%

Score: 6.1


Suggested Fix

Type: Upgrade version

Origin: GHSA-9v3m-8fp8-mj99

Release Date: Feb 20, 2019 04:00 PM

Fix Resolution : bootstrap-sass - 3.4.1,bootstrap - 4.3.1,org.webjars:bootstrap:3.4.1,org.webjars:bootstrap:4.3.1,bootstrap - 4.3.1,bootstrap.less - 3.4.1,bootstrap - 4.3.1,bootstrap.sass - 4.3.1,bootstrap - 3.4.1,bootstrap-sass - 3.4.1,bootstrap - 3.4.1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions