CVE-2019-8331 - Medium Severity Vulnerability
Vulnerable Library - bootstrap-3.3.7.tgz
The most popular front-end framework for developing responsive, mobile first projects on the web.
path: /IntranetNew/WebUI/ClientApp/node_modules/bootstrap/package.json
Library home page: https://registry.npmjs.org/bootstrap/-/bootstrap-3.3.7.tgz
Dependency Hierarchy:
- ❌ bootstrap-3.3.7.tgz (Vulnerable Library)
Vulnerability Details
In Bootstrap before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Publish Date: 2019-02-20
URL: CVE-2019-8331
CVSS 2 Score Details (4.3)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: twbs/bootstrap#28236
Release Date: 2019-02-20
Fix Resolution: v4.3.1
Step up your Open Source Security Game with WhiteSource here
CVE-2019-8331 - Medium Severity Vulnerability
The most popular front-end framework for developing responsive, mobile first projects on the web.
path: /IntranetNew/WebUI/ClientApp/node_modules/bootstrap/package.json
Library home page: https://registry.npmjs.org/bootstrap/-/bootstrap-3.3.7.tgz
Dependency Hierarchy:
In Bootstrap before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Publish Date: 2019-02-20
URL: CVE-2019-8331
Base Score Metrics not available
Type: Upgrade version
Origin: twbs/bootstrap#28236
Release Date: 2019-02-20
Fix Resolution: v4.3.1
Step up your Open Source Security Game with WhiteSource here