CVE-2018-20676

Description

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
6.144

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.2Windows
Vulnerabilities CVE-2018-14040,CVE-2018-20677,CVE-2018-20676,CVE-2016-10735,CVE-2018-14042 are fixed in WebJars - bootstrap 3.4.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.3Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0.3.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 22.0.2Windows
Vulnerabilities CVE-2018-20677,CVE-2018-20676 are fixed in Ruby-bootstrap 3.4.0Windows
Vulnerabilities CVE-2018-20677,CVE-2018-20676 are fixed in Nuget - bootstrap 3.4.0Windows
Vulnerabilities CVE-2018-20677,CVE-2018-20676 are fixed in Ruby-bootstrap-sass 3.4.0Windows
(RHSA-2020:3936) ipa security, bug fix, and enhancement update ipa-client-4.6.8-5.el7.x86_64.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update ipa-client-common-4.6.8-5.el7.noarch.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update ipa-common-4.6.8-5.el7.noarch.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update ipa-python-compat-4.6.8-5.el7.noarch.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update ipa-server-4.6.8-5.el7.x86_64.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update ipa-server-common-4.6.8-5.el7.noarch.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update ipa-server-dns-4.6.8-5.el7.noarch.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update ipa-server-trust-ad-4.6.8-5.el7.x86_64.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update python2-ipaclient-4.6.8-5.el7.noarch.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update python2-ipalib-4.6.8-5.el7.noarch.rpmLinux
(RHSA-2020:3936) ipa security, bug fix, and enhancement update python2-ipaserver-4.6.8-5.el7.noarch.rpmLinux
Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update python3-qrcode-5.1-12.module_el8.6.0+2737+7e73ea90.noarch.rpmLinux
Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update python3-qrcode-core-5.1-12.module_el8.6.0+2737+7e73ea90.noarch.rpmLinux
Vulnerabilities CVE-2018-14040,CVE-2018-20677,CVE-2018-20676,CVE-2016-10735,CVE-2018-14042 are fixed in WebJars - bootstrap for Linux 3.4.0Linux
Vulnerabilities CVE-2018-20677,CVE-2018-20676 are fixed in Ruby-bootstrap for Linux 3.4.0Linux
Vulnerabilities CVE-2018-20677,CVE-2018-20676 are fixed in Nuget - bootstrap for Linux 3.4.0Linux
Vulnerabilities CVE-2018-20677,CVE-2018-20676 are fixed in Ruby-bootstrap-sass for Linux 3.4.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234