We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.0.0/js/bootstrap.js
Path to vulnerable library: /Pro.Assur/Pro.Assur/Scripts/bootstrap.js
Dependency Hierarchy:
Sleek, intuitive, and powerful mobile first front-end framework for faster and easier web developmen...
Library home page: https://api.nuget.org/packages/bootstrap.3.0.0.nupkg
Path to dependency file: /Pro.Assur/Pro.Assur/packages.config
Path to vulnerable library: /Pro.Assur/Pro.Assur/packages.config
Found in HEAD commit: 42426d0c2443f0f0aa6029a94ba1583c43f28d50
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
Publish Date: 2018-07-13
URL: CVE-2018-14041
Base Score Metrics:
Type: Change files
Origin: twbs/bootstrap@3229efc
Release Date: 2018-05-30
Fix Resolution: Replace or update the following file: scrollspy.js
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered:
No branches or pull requests
CVE-2018-14041 - Medium Severity Vulnerability
Vulnerable Libraries - bootstrap-3.0.0.js, bootstrap.3.0.0.nupkg
bootstrap-3.0.0.js
The most popular front-end framework for developing responsive, mobile first projects on the web.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.0.0/js/bootstrap.js
Path to vulnerable library: /Pro.Assur/Pro.Assur/Scripts/bootstrap.js
Dependency Hierarchy:
bootstrap.3.0.0.nupkg
Sleek, intuitive, and powerful mobile first front-end framework for faster and easier web developmen...
Library home page: https://api.nuget.org/packages/bootstrap.3.0.0.nupkg
Path to dependency file: /Pro.Assur/Pro.Assur/packages.config
Path to vulnerable library: /Pro.Assur/Pro.Assur/packages.config
Dependency Hierarchy:
Found in HEAD commit: 42426d0c2443f0f0aa6029a94ba1583c43f28d50
Vulnerability Details
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
Publish Date: 2018-07-13
URL: CVE-2018-14041
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Change files
Origin: twbs/bootstrap@3229efc
Release Date: 2018-05-30
Fix Resolution: Replace or update the following file: scrollspy.js
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: