CVE-2019-8331

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 96.75%
Affected Products (NVD)
VendorProductVersion
getbootstrapbootstrap
𝑥
< 3.4.1
getbootstrapbootstrap
4.3.0 ≤
𝑥
< 4.3.1
f5big-ip_access_policy_manager
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_access_policy_manager
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_access_policy_manager
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_access_policy_manager
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_advanced_firewall_manager
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_advanced_firewall_manager
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_advanced_firewall_manager
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_advanced_firewall_manager
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_analytics
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_analytics
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_analytics
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_analytics
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_application_acceleration_manager
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_application_acceleration_manager
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_application_acceleration_manager
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_application_acceleration_manager
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_application_security_manager
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_application_security_manager
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_application_security_manager
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_application_security_manager
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_domain_name_system
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_domain_name_system
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_domain_name_system
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_domain_name_system
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_edge_gateway
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_edge_gateway
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_edge_gateway
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_edge_gateway
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_fraud_protection_service
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_fraud_protection_service
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_fraud_protection_service
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_fraud_protection_service
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_global_traffic_manager
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_global_traffic_manager
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_global_traffic_manager
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_global_traffic_manager
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_link_controller
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_link_controller
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_link_controller
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_link_controller
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_local_traffic_manager
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_local_traffic_manager
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_local_traffic_manager
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_local_traffic_manager
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_policy_enforcement_manager
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_policy_enforcement_manager
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_policy_enforcement_manager
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_policy_enforcement_manager
15.0.0 ≤
𝑥
< 15.1.0
f5big-ip_webaccelerator
12.1.0 ≤
𝑥
< 12.1.5.1
f5big-ip_webaccelerator
13.0.0 ≤
𝑥
< 13.1.3.4
f5big-ip_webaccelerator
14.0.0 ≤
𝑥
< 14.1.2.5
f5big-ip_webaccelerator
15.0.0 ≤
𝑥
< 15.1.0
redhatvirtualization_manager
4.3
tenabletenable.sc
𝑥
< 5.19.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
twitter-bootstrap3
bookworm
3.4.1+dfsg-3
fixed
bullseye
3.4.1+dfsg-2
fixed
jessie
no-dsa
sid
3.4.1+dfsg-3
fixed
stretch
no-dsa
trixie
3.4.1+dfsg-3
fixed
twitter-bootstrap4
bookworm
4.6.1+dfsg1-4
fixed
bullseye
4.5.2+dfsg1-8~deb11u1
fixed
jessie
no-dsa
sid
4.6.1+dfsg1-4
fixed
stretch
no-dsa
trixie
4.6.1+dfsg1-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
twitter-bootstrap
bionic
needs-triage
cosmic
ignored
disco
ignored
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
resolute
dne
trusty
dne
xenial
ignored
twitter-bootstrap3
bionic
needed
cosmic
ignored
disco
ignored
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
trusty
dne
xenial
ignored
twitter-bootstrap4
bionic
dne
cosmic
dne
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
trusty
dne
xenial
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ipa-client
RHEL 7
0:4.6.8-5.el7
fixed
ipa-client-common
RHEL 7
0:4.6.8-5.el7
fixed
ipa-common
RHEL 7
0:4.6.8-5.el7
fixed
ipa-python-compat
RHEL 7
0:4.6.8-5.el7
fixed
ipa-server
RHEL 7
0:4.6.8-5.el7
fixed
ipa-server-common
RHEL 7
0:4.6.8-5.el7
fixed
ipa-server-dns
RHEL 7
0:4.6.8-5.el7
fixed
ipa-server-trust-ad
RHEL 7
0:4.6.8-5.el7
fixed
python2-ipaclient
RHEL 7
0:4.6.8-5.el7
fixed
python2-ipalib
RHEL 7
0:4.6.8-5.el7
fixed
python2-ipaserver
RHEL 7
0:4.6.8-5.el7
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
ipa-client
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-client-common
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-common
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-debuginfo
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-python-compat
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-server
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-server-common
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-server-dns
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
ipa-server-trust-ad
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
python2-ipaclient
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
python2-ipalib
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
python2-ipaserver
Amazon Linux 2
0:4.6.8-5.amzn2
fixed
References