Back

MEDIUM

bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip

Published Jul 13, 2018

Description

In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

Affected products

Remediation

Red Hat statement

Red Hat Satellite 6.2 and newer versions don't use the bootstrap library, hence are not affected by this flaw. Red Hat CloudForms 4.6 and newer versions include the vulnerable component, but there is no risk of exploitation, since there is no possible vector to access the vulnerability. Older Red Hat CloudForms versions don't use the vulnerable component at all. Red Hat Enterprise Satellite 5 is now in Maintenance Support 2 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Satellite 5 Life Cycle: https://access.redhat.com/support/policy/updates/satellite.

Metrics

References (33)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 13, 2018
Updated Aug 5, 2024
Reserved Jul 13, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 29, 2018
GHSA-7MVR-5X2G-WFC8