VulnerabilityModified
CVE-2016-10735
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
MEDIUM 6.1EPSS 4.04%
Does this matter?
Lower severity and a low EPSS score (4.04%). Track it; it rarely justifies an emergency change on its own.
Description
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.04% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- getbootstrap/bootstrap
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHBA-2019:1076
- https://access.redhat.com/errata/RHBA-2019:1570
- https://access.redhat.com/errata/RHSA-2019:1456
- https://access.redhat.com/errata/RHSA-2019:3023
- https://access.redhat.com/errata/RHSA-2020:0132
- https://access.redhat.com/errata/RHSA-2020:0133
- https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/Release Notes, Third Party Advisory
- https://github.com/twbs/bootstrap/issues/20184Exploit, Issue Tracking, Third Party Advisory
- https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906Issue Tracking, Third Party Advisory
- https://github.com/twbs/bootstrap/pull/23679Third Party Advisory
- https://github.com/twbs/bootstrap/pull/23687Patch, Third Party Advisory
- https://github.com/twbs/bootstrap/pull/26460Third Party Advisory
- https://www.tenable.com/security/tns-2021-14
- https://access.redhat.com/errata/RHBA-2019:1076
- https://access.redhat.com/errata/RHBA-2019:1570
- https://access.redhat.com/errata/RHSA-2019:1456
- https://access.redhat.com/errata/RHSA-2019:3023
- https://access.redhat.com/errata/RHSA-2020:0132
- https://access.redhat.com/errata/RHSA-2020:0133
- https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/Release Notes, Third Party Advisory
- https://github.com/twbs/bootstrap/issues/20184Exploit, Issue Tracking, Third Party Advisory
- https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906Issue Tracking, Third Party Advisory
- https://github.com/twbs/bootstrap/pull/23679Third Party Advisory
- https://github.com/twbs/bootstrap/pull/23687Patch, Third Party Advisory
- https://github.com/twbs/bootstrap/pull/26460Third Party Advisory
- https://www.tenable.com/security/tns-2021-14
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.