CVE-2019-8331

Severity
6.1MEDIUM
EPSS
1.7%
top 17.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateAug 2

Description

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages29 packages

NuGetbootstrap4.0.04.3.1+1
RubyGemsbootstrap< 4.3.1
npmbootstrap4.0.04.3.1+1
NuGetBootstrap.Less3.0.03.4.1
NuGetbootstrap.sass< 4.3.1

Patches

🔴Vulnerability Details

4
OSV
Bootstrap Vulnerable to Cross-Site Scripting2019-02-22
GHSA
Bootstrap Vulnerable to Cross-Site Scripting2019-02-22
OSV
CVE-2019-8331: In Bootstrap before 32019-02-20
CVEList
CVE-2019-8331: In Bootstrap before 32019-02-20

📋Vendor Advisories

2
Red Hat
bootstrap: XSS in the tooltip or popover data-template attribute2019-02-11
Debian
CVE-2019-8331: twitter-bootstrap3 - In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip...2019

💬Community

7
HackerOne
Vulnerable javascript dependency at Main domain2021-08-02
HackerOne
Cross-site Scripting (XSS) possible at https://sifchain.finance// via CVE-2019-8331 exploitation2021-06-21
Bugzilla
CVE-2019-8331 rubygem-bootstrap-sass: bootstrap: XSS in the tooltip or popover data-template attribute [fedora-all]2019-03-07
Bugzilla
CVE-2019-8331 bootstrap: XSS in the tooltip or popover data-template attribute2019-03-07
Bugzilla
CVE-2019-8331 python-XStatic-Bootstrap-SCSS: bootstrap: XSS in the tooltip or popover data-template attribute [openstack-rdo]2019-03-07