In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.
Update twbs/bootstrap to 4.1.2; twbs/bootstrap to 3.4.0; org.webjars:bootstrap to 4.1.2; org.webjars:bootstrap to 3.4.0; bootstrap to 4.1.2; bootstrap to 3.4.0; bootstrap-sass to 3.4.0; bootstrap to 4.1.2; bootstrap to 3.4.0; bootstrap.sass to 4.1.2; bootstrap to 4.1.2; bootstrap to 3.4.0; bootstrap-sass to 3.4.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBootstrap Cross-site Scripting vulnerability affects twbs/bootstrap (composer), twbs/bootstrap (composer), org.webjars:bootstrap (maven), org.webjars:bootstrap (maven), bootstrap (npm), bootstrap (npm), bootstrap-sass (npm), bootstrap (nuget), bootstrap (nuget), bootstrap.sass (nuget), bootstrap (rubygems), bootstrap (rubygems), bootstrap-sass (rubygems). Severity is medium. In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.
AI coding agents often install or upgrade packages automatically in composer, maven, npm, nuget and rubygems. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.
Update twbs/bootstrap to 4.1.2; twbs/bootstrap to 3.4.0; org.webjars:bootstrap to 4.1.2; org.webjars:bootstrap to 3.4.0; bootstrap to 4.1.2; bootstrap to 3.4.0; bootstrap-sass to 3.4.0; bootstrap to 4.1.2; bootstrap to 3.4.0; bootstrap.sass to 4.1.2; bootstrap to 4.1.2; bootstrap to 3.4.0; bootstrap-sass to 3.4.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanBootstrap Cross-site Scripting vulnerability affects twbs/bootstrap (composer), twbs/bootstrap (composer), org.webjars:bootstrap (maven), org.webjars:bootstrap (maven), bootstrap (npm), bootstrap (npm), bootstrap-sass (npm), bootstrap (nuget), bootstrap (nuget), bootstrap.sass (nuget), bootstrap (rubygems), bootstrap (rubygems), bootstrap-sass (rubygems). Severity is medium. In Bootstrap starting in version 2.3.0 and prior to versions 3.4.0 and 4.1.2, XSS is possible in the data-container property of tooltip. This is similar to CVE-2018-14041.
AI coding agents often install or upgrade packages automatically in composer, maven, npm, nuget and rubygems. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| twbs/bootstrapcomposer |
|---|
| >=4.0.0,<4.1.2 |
| 4.1.2 |
| twbs/bootstrapcomposer | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| org.webjars:bootstrapmaven | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| org.webjars:bootstrapmaven | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| bootstrapnpm | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| bootstrapnpm | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| bootstrap-sassnpm | >=2.0.4,<3.4.0 | 3.4.0 |
|---|
| bootstrapnuget | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| bootstrapnuget | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| bootstrap.sassnuget | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| bootstraprubygems | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| bootstraprubygems | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| bootstrap-sassrubygems | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| twbs/bootstrapcomposer |
|---|
| >=4.0.0,<4.1.2 |
| 4.1.2 |
| twbs/bootstrapcomposer | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| org.webjars:bootstrapmaven | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| org.webjars:bootstrapmaven | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| bootstrapnpm | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| bootstrapnpm | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| bootstrap-sassnpm | >=2.0.4,<3.4.0 | 3.4.0 |
|---|
| bootstrapnuget | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| bootstrapnuget | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| bootstrap.sassnuget | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| bootstraprubygems | >=4.0.0,<4.1.2 | 4.1.2 |
|---|
| bootstraprubygems | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
| bootstrap-sassrubygems | >=2.3.0,<3.4.0 | 3.4.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard