CVE-2016-10735

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 89.9%
Affected Products (NVD)
VendorProductVersion
getbootstrapbootstrap
3.0.0 ≤
𝑥
< 3.4.0
getbootstrapbootstrap
4.0.0:beta
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
twitter-bootstrap3
bookworm
3.4.1+dfsg-3
fixed
bullseye
3.4.1+dfsg-2
fixed
jessie
no-dsa
sid
3.4.1+dfsg-3
fixed
trixie
3.4.1+dfsg-3
fixed
twitter-bootstrap4
bookworm
4.6.1+dfsg1-4
fixed
bullseye
4.5.2+dfsg1-8~deb11u1
fixed
jessie
no-dsa
sid
4.6.1+dfsg1-4
fixed
trixie
4.6.1+dfsg1-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
twitter-bootstrap3
bionic
needed
cosmic
ignored
disco
Fixed 3.4.0+dfsg-1
released
eoan
Fixed 3.4.0+dfsg-1
released
focal
Fixed 3.4.0+dfsg-1
released
groovy
Fixed 3.4.0+dfsg-1
released
hirsute
Fixed 3.4.0+dfsg-1
released
impish
Fixed 3.4.0+dfsg-1
released
jammy
Fixed 3.4.0+dfsg-1
released
kinetic
Fixed 3.4.0+dfsg-1
released
lunar
Fixed 3.4.0+dfsg-1
released
mantic
Fixed 3.4.0+dfsg-1
released
noble
Fixed 3.4.0+dfsg-1
released
oracular
Fixed 3.4.0+dfsg-1
released
plucky
Fixed 3.4.0+dfsg-1
released
questing
Fixed 3.4.0+dfsg-1
released
resolute
Fixed 3.4.0+dfsg-1
released
trusty
dne
xenial
needed
twitter-bootstrap
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
resolute
dne
trusty
dne
xenial
not-affected
twitter-bootstrap4
bionic
dne
cosmic
dne
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
trusty
dne
xenial
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ipa-client
RHEL 7
0:4.6.8-5.el7
fixed
ipa-client-common
RHEL 7
0:4.6.8-5.el7
fixed
ipa-common
RHEL 7
0:4.6.8-5.el7
fixed
ipa-python-compat
RHEL 7
0:4.6.8-5.el7
fixed
ipa-server
RHEL 7
0:4.6.8-5.el7
fixed
ipa-server-common
RHEL 7
0:4.6.8-5.el7
fixed
ipa-server-dns
RHEL 7
0:4.6.8-5.el7
fixed
ipa-server-trust-ad
RHEL 7
0:4.6.8-5.el7
fixed
python2-ipaclient
RHEL 7
0:4.6.8-5.el7
fixed
python2-ipalib
RHEL 7
0:4.6.8-5.el7
fixed
python2-ipaserver
RHEL 7
0:4.6.8-5.el7
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
ipa-client
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-client-common
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-common
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-debuginfo
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-python-compat
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-server
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-server-common
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-server-dns
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-server-trust-ad
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
python2-ipaclient
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
python2-ipalib
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
python2-ipaserver
Amazon Linux 2
0:4.6.8-5.amzn2
fixed