XSS in Bootstrap button component
Published Jul 11, 2024
6.4
MEDIUMCVSS 3.1
EPSS 0.49%
Description
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
Affected products
-
- Version 1.4.0StatusaffectedConstraints<=3.4.1
- Version
-
- Version 2.3.2StatusaffectedConstraints<=3.4.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Bootstrap | Bootstrap | unaffected |
| ||||||
| Bootstrap-sass | Bootstrap-Sass | unaffected |
|
No data.
-
- Version 2.0.0StatusaffectedConstraints<=3.4.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Getbootstrap | Bootstrap | n/a |
|
Discovery 1 for RHEL 9
discovery/discovery-server-rhel9:1.12.0-1
Fixed · RHSA-2025:1249
Discovery 1 for RHEL 9
discovery/discovery-ui-rhel9:1.12.0-1
Fixed · RHSA-2025:1249
Red Hat AMQ Broker 7
bootstrap
Fix deferred
Red Hat Build of Keycloak
bootstrap
Not affected
Red Hat Ceph Storage 4
ceph
Out of support scope
Red Hat Ceph Storage 5
ceph
Out of support scope
Red Hat Ceph Storage 6
ceph
Not affected
Red Hat Ceph Storage 7
ceph
Not affected
Red Hat Certification for Red Hat Enterprise Linux 7
redhat-certification
Affected
Red Hat Enterprise Linux 10
ceph
Fix deferred
Red Hat Enterprise Linux 7
firefox
Affected
Red Hat Enterprise Linux 8
389-ds:1.4/389-ds-base
Not affected
Red Hat Enterprise Linux 8
cockpit
Not affected
Red Hat Enterprise Linux 8
cockpit-appstream
Not affected
Red Hat Enterprise Linux 8
cockpit-composer
Will not fix
Red Hat Enterprise Linux 8
container-tools:rhel8/cockpit-podman
Not affected
Red Hat Enterprise Linux 8
dotnet5.0-build-reference-packages
Will not fix
Red Hat Enterprise Linux 8
dotnet9.0
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 9
ceph
Fix deferred
Red Hat Enterprise Linux 9
cockpit-composer
Will not fix
Red Hat Enterprise Linux 9
dotnet9.0
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat Fuse 7
bootstrap
Out of support scope
Red Hat JBoss Data Grid 7
bootstrap
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
bootstrap
Not affected
Red Hat JBoss Enterprise Application Platform 8
bootstrap
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
bootstrap
Not affected
Red Hat OpenStack Platform 16.2
qpid-dispatch
Affected
Red Hat Process Automation 7
bootstrap
Out of support scope
Red Hat Quay 3
quay/quay-rhel8
Not affected
Red Hat Satellite 6
nodejs-patternfly-react-catalog-view-extension
Not affected
Red Hat Single Sign-On 7
bootstrap
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Discovery 1 for RHEL 9 | discovery/discovery-server-rhel9:1.12.0-1 | Fixed | RHSA-2025:1249 |
| Discovery 1 for RHEL 9 | discovery/discovery-ui-rhel9:1.12.0-1 | Fixed | RHSA-2025:1249 |
| Red Hat AMQ Broker 7 | bootstrap | Fix deferred | n/a |
| Red Hat Build of Keycloak | bootstrap | Not affected | n/a |
| Red Hat Ceph Storage 4 | ceph | Out of support scope | n/a |
| Red Hat Ceph Storage 5 | ceph | Out of support scope | n/a |
| Red Hat Ceph Storage 6 | ceph | Not affected | n/a |
| Red Hat Ceph Storage 7 | ceph | Not affected | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 7 | redhat-certification | Affected | n/a |
| Red Hat Enterprise Linux 10 | ceph | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | firefox | Affected | n/a |
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit-appstream | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit-composer | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/cockpit-podman | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet5.0-build-reference-packages | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | ceph | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | cockpit-composer | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | dotnet9.0 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat Fuse 7 | bootstrap | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | bootstrap | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | bootstrap | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | bootstrap | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | bootstrap | Not affected | n/a |
| Red Hat OpenStack Platform 16.2 | qpid-dispatch | Affected | n/a |
| Red Hat Process Automation 7 | bootstrap | Out of support scope | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | n/a |
| Red Hat Satellite 6 | nodejs-patternfly-react-catalog-view-extension | Not affected | n/a |
| Red Hat Single Sign-On 7 | bootstrap | Out of support scope | n/a |
bootstrap
npm
Introduced 1.4.0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | bootstrap | 1.4.0 | not fixed |
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2024-6485 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297388 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2429 Advisory
- https://github.com/advisories/GHSA-vxmc-5x29-h64v Advisory
- https://lists.debian.org/debian-lts-announce/2025/04/msg00020.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-6485
- https://www.cve.org/CVERecord?id=CVE-2024-6485
- https://www.herodevs.com/vulnerability-directory/cve-2024-6485
Change history (0)
No recorded changes yet.