CVE-2019-8331
published 2019-02-20CVE-2019-8331: In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
PriorityP335medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
16.86%
96.7th percentile
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bootstrap-sass | bootstrap-sass | >= 3.0.0 < 3.4.1 | 3.4.1 |
| bootstrap-sass | bootstrap-sass | >= 3.0.0 < 3.4.1 | 3.4.1 |
| debian | twitter-bootstrap3 | < twitter-bootstrap3 3.4.1+dfsg-1 (bookworm) | twitter-bootstrap3 3.4.1+dfsg-1 (bookworm) |
| debian | twitter-bootstrap4 | < twitter-bootstrap3 3.4.1+dfsg-1 (bookworm) | twitter-bootstrap3 3.4.1+dfsg-1 (bookworm) |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
| f5 | big-ip_access_policy_manager | >= 13.0.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_access_policy_manager | >= 14.0.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_access_policy_manager | >= 15.0.0 < 15.1.0 | 15.1.0 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
| f5 | big-ip_advanced_firewall_manager | >= 13.0.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_advanced_firewall_manager | >= 14.0.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_advanced_firewall_manager | >= 15.0.0 < 15.1.0 | 15.1.0 |
| f5 | big-ip_analytics | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
| f5 | big-ip_analytics | >= 13.0.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_analytics | >= 14.0.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_analytics | >= 15.0.0 < 15.1.0 | 15.1.0 |
| f5 | big-ip_application_acceleration_manager | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
| f5 | big-ip_application_acceleration_manager | >= 13.0.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_application_acceleration_manager | >= 14.0.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_application_acceleration_manager | >= 15.0.0 < 15.1.0 | 15.1.0 |
| f5 | big-ip_application_security_manager | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
| f5 | big-ip_application_security_manager | >= 13.0.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_application_security_manager | >= 14.0.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_application_security_manager | >= 15.0.0 < 15.1.0 | 15.1.0 |
| f5 | big-ip_domain_name_system | >= 12.1.0 < 12.1.5.1 | 12.1.5.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
CISA ICS
Mitsubishi Electric EcoWebServerIII
cisa_ics·2022-02-24·CVSS 6.1
[MEDIUM] Mitsubishi Electric EcoWebServerIII
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric EcoWebServerIII
Last RevisedFebruary 24, 2022
Alert CodeICSA-22-055-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Mitsubishi Electric Corporation
- Equipment: Energy Saving Data Collecting Server (EcoWebServerIII)
- Vulnerabilities: Improper Neutralization of Input During Web Page Generation, Uncontrolled Resource Consumption, Improperly Controlled Modification of Dynamically-Determined Object Attributes
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow informa
Red Hat
bootstrap: XSS in the tooltip or popover data-template attribute
vendor_redhat·2019-02-11·CVSS 6.1
CVE-2019-8331 [MEDIUM] CWE-79 bootstrap: XSS in the tooltip or popover data-template attribute
bootstrap: XSS in the tooltip or popover data-template attribute
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
A cross-site scripting vulnerability was discovered in bootstrap. If an attacker could control the data given to tooltip or popover, they could inject HTML or Javascript into the rendered page when tooltip or popover events fired.
Statement: Red Hat CloudForms 4.6 and newer versions include the vulnerable component, but there is no risk of exploitation since there is no possible vector to access the vulnerability. Older Red Hat CloudForms versions don't use the vulnerable component at all.
Package: cfme-gemset (CloudForms Management Engine 5) - Not affected
Package: bootstrap (Red Hat 3scale API Management
Debian
CVE-2019-8331: twitter-bootstrap3 - In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip...
vendor_debian·2019·CVSS 6.1
CVE-2019-8331 [MEDIUM] CVE-2019-8331: twitter-bootstrap3 - In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip...
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Scope: local
bookworm: resolved (fixed in 3.4.1+dfsg-1)
bullseye: resolved (fixed in 3.4.1+dfsg-1)
forky: resolved (fixed in 3.4.1+dfsg-1)
sid: resolved (fixed in 3.4.1+dfsg-1)
trixie: resolved (fixed in 3.4.1+dfsg-1)
GHSA
GHSA-w8pw-mmh7-x243: In Splunk Enterprise versions below 9
ghsa_unreviewed·2023-06-01·CVSS 6.1
CVE-2023-32711 [MEDIUM] CWE-79 GHSA-w8pw-mmh7-x243: In Splunk Enterprise versions below 9
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, a Splunk dashboard view lets a low-privileged user exploit a vulnerability in the Bootstrap web framework (CVE-2019-8331) and build a stored cross-site scripting (XSS) payload.
OSV
Bootstrap Vulnerable to Cross-Site Scripting
osv·2019-02-22
CVE-2019-8331 [MEDIUM] Bootstrap Vulnerable to Cross-Site Scripting
Bootstrap Vulnerable to Cross-Site Scripting
Versions of `bootstrap` prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The `data-template` attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
## Recommendation
For `bootstrap` 4.x upgrade to 4.3.1 or later.
For `bootstrap` 3.x upgrade to 3.4.1 or later.
GHSA
Bootstrap Vulnerable to Cross-Site Scripting
ghsa·2019-02-22
CVE-2019-8331 [MEDIUM] CWE-79 Bootstrap Vulnerable to Cross-Site Scripting
Bootstrap Vulnerable to Cross-Site Scripting
Versions of `bootstrap` prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The `data-template` attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
## Recommendation
For `bootstrap` 4.x upgrade to 4.3.1 or later.
For `bootstrap` 3.x upgrade to 3.4.1 or later.
OSV
CVE-2019-8331: In Bootstrap before 3
osv·2019-02-20·CVSS 6.1
CVE-2019-8331 [MEDIUM] CVE-2019-8331: In Bootstrap before 3
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
No detection rules found.
No public exploits indexed.
HackerOne
Vulnerable javascript dependency at Main domain
hackerone·2021-08-02·CVSS 6.1
CVE-2019-8331 [MEDIUM] Vulnerable javascript dependency at Main domain
Vulnerable javascript dependency at Main domain
Hello,
Issue detail,
Burp observed 1 outdated JavaScript libraries with 4 known vulnerabilities.
Burp detected bootstrap version 4.0.0, which has the following vulnerabilities:
CVE-2019-8331: XSS in data-template, data-content and data-title properties of tooltip/popover
CVE-2018-14041: XSS in data-target property of scrollspy
CVE-2018-14040: XSS in collapse data-parent attribute
CVE-2018-14042: XSS in data-container property of tooltip
Host: https://sifchain.finance
Path: /wp-content/themes/icos/assets/js/vendor/bootstrap.min.js
{F1293110}
## Impact
Potential XSS
HackerOne
Cross-site Scripting (XSS) possible at https://sifchain.finance// via CVE-2019-8331 exploitation
hackerone·2021-06-21·CVSS 6.1
CVE-2019-8331 [MEDIUM] Cross-site Scripting (XSS) possible at https://sifchain.finance// via CVE-2019-8331 exploitation
Cross-site Scripting (XSS) possible at https://sifchain.finance// via CVE-2019-8331 exploitation
## Summary:
https://sifchain.finance is using Bootstrap framework version 4.0.0 which is =4.0.0
4. Visit https://sifchain.finance/wp-content/themes/icos/assets/js/vendor/bootstrap.min.js?ver=5.7.2
5. You'll get the Bootstrap Version, Which is v4.0.0 and its vulnerable to Cross-site Scripting (XSS)
##Details about Bug:
A cross-site scripting attack occurs when the attacker tricks a legitimate web-based application or site to accept a request as originating from a trusted source.
This is done by escaping the context of the web application; the web application then delivers that data to its users along with other trusted dynamic content, without validating it. The browser unknowingly executes m
Bugzilla
CVE-2019-8331 rubygem-bootstrap-sass: bootstrap: XSS in the tooltip or popover data-template attribute [fedora-all]
bugzilla·2019-03-07·CVSS 6.1
CVE-2019-8331 [MEDIUM] CVE-2019-8331 rubygem-bootstrap-sass: bootstrap: XSS in the tooltip or popover data-template attribute [fedora-all]
CVE-2019-8331 rubygem-bootstrap-sass: bootstrap: XSS in the tooltip or popover data-template attribute [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2019-8331 bootstrap: XSS in the tooltip or popover data-template attribute
bugzilla·2019-03-07·CVSS 6.1
CVE-2019-8331 [MEDIUM] CVE-2019-8331 bootstrap: XSS in the tooltip or popover data-template attribute
CVE-2019-8331 bootstrap: XSS in the tooltip or popover data-template attribute
A vulnerability was found in Bootstrap before 4.3.1. An XSS is possible in the tooltip or popover data-template attribute.
References:
https://github.com/twbs/bootstrap/releases/tag/v4.3.1
Upstream Patch:
https://github.com/twbs/bootstrap/pull/28236
Discussion:
Created python-XStatic-Bootstrap-SCSS tracking bugs for this issue:
Affects: epel-7 [bug 1686455]
Affects: fedora-all [bug 1686456]
Affects: openstack-rdo [bug 1686458]
Created rubygem-bootstrap-sass tracking bugs for this issue:
Affects: fedora-all [bug 1686457]
---
Red Hat OpenStack Platform versions 8, 9, 10, 13, & 14 are affected by this vulnerability.
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7
Bugzilla
CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [openstack-rdo]
bugzilla·2019-03-07·CVSS 6.1
CVE-2019-8331 [MEDIUM] CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [openstack-rdo]
CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [epel-7]
bugzilla·2019-03-07·CVSS 6.1
CVE-2019-8331 [MEDIUM] CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [epel-7]
CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Us
Bugzilla
CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [fedora-all]
bugzilla·2019-03-07·CVSS 6.1
CVE-2019-8331 [MEDIUM] CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [fedora-all]
CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.htmlhttp://seclists.org/fulldisclosure/2019/May/10http://seclists.org/fulldisclosure/2019/May/11http://seclists.org/fulldisclosure/2019/May/13http://www.securityfocus.com/bid/107375https://access.redhat.com/errata/RHSA-2019:1456https://access.redhat.com/errata/RHSA-2019:3023https://access.redhat.com/errata/RHSA-2019:3024https://blog.getbootstrap.com/2019/02/13/bootstrap-4-3-1-and-3-4-1/https://github.com/twbs/bootstrap/pull/28236https://github.com/twbs/bootstrap/releases/tag/v3.4.1https://github.com/twbs/bootstrap/releases/tag/v4.3.1https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%3Ehttps://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e%40%3Cdev.superset.apache.org%3Ehttps://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r3dc0cac8d856bca02bd6997355d7ff83027dcfc82f8646a29b89b714%40%3Cissues.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3Ehttps://seclists.org/bugtraq/2019/May/18https://support.f5.com/csp/article/K24383845https://support.f5.com/csp/article/K24383845?utm_source=f5support&%3Butm_medium=RSShttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.tenable.com/security/tns-2021-14http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.htmlhttp://seclists.org/fulldisclosure/2019/May/10http://seclists.org/fulldisclosure/2019/May/11http://seclists.org/fulldisclosure/2019/May/13http://www.securityfocus.com/bid/107375https://access.redhat.com/errata/RHSA-2019:1456https://access.redhat.com/errata/RHSA-2019:3023https://access.redhat.com/errata/RHSA-2019:3024https://blog.getbootstrap.com/2019/02/13/bootstrap-4-3-1-and-3-4-1/https://github.com/twbs/bootstrap/pull/28236https://github.com/twbs/bootstrap/releases/tag/v3.4.1https://github.com/twbs/bootstrap/releases/tag/v4.3.1https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%3Ehttps://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e%40%3Cdev.superset.apache.org%3Ehttps://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3Ehttps://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3Ehttps://lists.apache.org/thread.html/r3dc0cac8d856bca02bd6997355d7ff83027dcfc82f8646a29b89b714%40%3Cissues.hbase.apache.org%3Ehttps://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3Ehttps://seclists.org/bugtraq/2019/May/18https://support.f5.com/csp/article/K24383845https://support.f5.com/csp/article/K24383845?utm_source=f5support&%3Butm_medium=RSShttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.tenable.com/security/tns-2021-14
2019-02-20
Published