Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign upXSS vulnerable bootstrap version needs to be upgraded to 4.0.0 #4754
Comments
simonpasquier
added
help wanted
component/ui
labels
Oct 18, 2018
This comment has been minimized.
This comment has been minimized.
x86party
commented
Oct 22, 2018
•
|
Possibly a duplicate of #3494. |
This comment has been minimized.
This comment has been minimized.
ksherryBAE
commented
Oct 23, 2018
|
Does this issue still require fixing? |
This comment has been minimized.
This comment has been minimized.
|
@ksherryBAE yes, very much. It's the known vulnerability that's getting shipped with Prometheus. |
This comment has been minimized.
This comment has been minimized.
ksherryBAE
commented
Oct 23, 2018
|
Ok, I will have a look at it. |
This comment has been minimized.
This comment has been minimized.
|
@ksherryBAE thanks. |
This comment has been minimized.
This comment has been minimized.
ksherryBAE
commented
Oct 23, 2018
|
Current plan is to bring in bootstrap v4.0.0 and then go through all the templates and ensure that all the tags and functionality is up to date |
This comment has been minimized.
This comment has been minimized.
|
@ksherryBAE thanks, that sounds awesome. Also, would it be possible to backport the fix to release 2.3.1? |
This comment has been minimized.
This comment has been minimized.
|
@harche FYI we may only backport patches to the current stable release. |
This comment has been minimized.
This comment has been minimized.
|
@simonpasquier No problem. Thanks. |
This comment has been minimized.
This comment has been minimized.
ksherryBAE
commented
Oct 26, 2018
|
Just to quickly check, glyphicons are no longer supported in bootstrap 4.0.0 however there is a work around utilising https://github.com/Darkseal/bootstrap4-glyphicons |
This comment has been minimized.
This comment has been minimized.
|
Hi, i've also been contributing to this with ksherryBAE; i'll be making the pull request soon. |
achiuBAE
referenced this issue
Nov 5, 2018
Closed
web: Update from bootstrap 3.3.1 to bootstrap 4.0.0 #4821
This comment has been minimized.
This comment has been minimized.
dbambro
commented
Nov 27, 2018
|
The following are bootstrap 3.3.1 XSS vulnerabilities: |
This comment has been minimized.
This comment has been minimized.
|
Closed by #5226 |
harche commentedOct 18, 2018
Proposal
Use case. Why is this important?
Bootstrap version included is vulnerable for XSS attack, https://snyk.io/test/npm/bootstrap/3.3.1
It needs to be upgraded to 4.0.0
Bug Report
What did you do?
Everything works fine but the bootstrap js lib included has XSS vulnerability so needs to be upgraded
What did you expect to see?
N/A
What did you see instead? Under which circumstances?
N/A
Environment
N/A
System information:
N/A
Prometheus version:
The XSS vulnerable bootstrap js lib exists even in master branch, https://github.com/prometheus/prometheus/tree/master/web/ui/static/vendor/bootstrap-3.3.1
Alertmanager version:
N/A
Prometheus configuration file: