Bootstrap CVE-2019-8331 Cross Site Scripting Vulnerabilitiy
BID:107375
CVE-2019-8331 |Info
Bootstrap CVE-2019-8331 Cross Site Scripting Vulnerabilitiy
| Bugtraq ID: | 107375 |
| Class: | Design Error |
| CVE: |
CVE-2019-8331 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2019 12:00AM |
| Updated: | Mar 07 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Pivotal Cloud Foundry Ops Manager 2.4 Pivotal Cloud Foundry Ops Manager 2.3 Pivotal Cloud Foundry Ops Manager 2.2 getbootstrap Bootstrap 4.3 getbootstrap Bootstrap 4.2.1 getbootstrap Bootstrap 4.2 getbootstrap Bootstrap 3.4 |
| Not Vulnerable: |
Pivotal Cloud Foundry Ops Manager 2.4.5 Pivotal Cloud Foundry Ops Manager 2.3.11 Pivotal Cloud Foundry Ops Manager 2.2.19 getbootstrap Bootstrap 4.3.1 |
Discussion
Bootstrap CVE-2019-8331 Cross Site Scripting Vulnerabilitiy
Bootstrap is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to Bootstrap 4.3.1 are vulnerable.
Bootstrap is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to Bootstrap 4.3.1 are vulnerable.
Exploit / POC
Bootstrap CVE-2019-8331 Cross Site Scripting Vulnerabilitiy
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Bootstrap CVE-2019-8331 Cross Site Scripting Vulnerabilitiy
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Bootstrap CVE-2019-8331 Cross Site Scripting Vulnerabilitiy
References:
References:
- sanitize template option for tooltip/popover plugins #28236 (getbootstrap)
- Bootstrap releases (getbootstrap)
- getbootstrap Homepage (getbootstrap)
- Pivotal Homepage (Pivotal)
- CVE-2019-8331: Bootstrap XSS (Pivotal)