Back

MEDIUM

bootstrap: XSS in the affix configuration target property

Published Jan 9, 2019

Description

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

Affected products

Remediation

Red Hat statement

Red Hat CloudForms 4.6 and newer versions include the vulnerable component, but there is no risk of exploitation, since there is no possible vector to access the vulnerability. Older Red Hat CloudForms versions do not use the vulnerable component at all. Red Hat Virtualization 4.2 EUS contains the affected version of bootstrap in the packages ovirt-js-dependencies and ovirt-engine-dashboard. These packages are deprecated in Red Hat Virtualization 4.3.

Metrics

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 9, 2019
Updated Aug 5, 2024
Reserved Jan 8, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 10, 2018
GHSA-PH58-4VRJ-W6HR