Vulnerability Description
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getbootstrap | Bootstrap | < 3.4.1 |
| F5 | Big-Ip Access Policy Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Advanced Firewall Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Analytics | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Application Acceleration Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Application Security Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Domain Name System | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Edge Gateway | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Fraud Protection Service | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Global Traffic Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Link Controller | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Local Traffic Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Policy Enforcement Manager | >= 12.1.0, < 12.1.5.1 |
| F5 | Big-Ip Webaccelerator | >= 12.1.0, < 12.1.5.1 |
| Redhat | Virtualization Manager | 4.3 |
| Tenable | Tenable.Sc | < 5.19.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.htmThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/May/10Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/May/11Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/May/13Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/107375Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1456Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3023Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3024Third Party Advisory
- https://blog.getbootstrap.com/2019/02/13/bootstrap-4-3-1-and-3-4-1/Vendor Advisory
- https://github.com/twbs/bootstrap/pull/28236Issue TrackingPatchThird Party Advisory
- https://github.com/twbs/bootstrap/releases/tag/v3.4.1ProductThird Party Advisory
- https://github.com/twbs/bootstrap/releases/tag/v4.3.1Release NotesThird Party Advisory
- https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423
- https://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afe
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e
FAQ
What is CVE-2019-8331?
CVE-2019-8331 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
How severe is CVE-2019-8331?
CVE-2019-8331 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8331?
Check the references section above for vendor advisories and patch information. Affected products include: Getbootstrap Bootstrap, F5 Big-Ip Access Policy Manager, F5 Big-Ip Advanced Firewall Manager, F5 Big-Ip Analytics, F5 Big-Ip Application Acceleration Manager.