Back

MEDIUM

bootstrap: XSS in the tooltip or popover data-template attribute

Published Feb 20, 2019

Description

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

Affected products

Remediation

Red Hat statement

Red Hat CloudForms 4.6 and newer versions include the vulnerable component, but there is no risk of exploitation since there is no possible vector to access the vulnerability. Older Red Hat CloudForms versions don't use the vulnerable component at all.

Metrics

References (48)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2019
Updated Aug 4, 2024
Reserved Feb 13, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 11, 2019
GHSA-9V3M-8FP8-MJ99