CVE-2018-20677
bootstrap: XSS in the affix configuration target property
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
En Bootstrap, en versiones anteriores a la 3.4.0, Cross-Site Scripting (XSS) es posible en la propiedad "affix" en la configuración.
A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting caused by improper validation of user-supplied input by the affix configuration target property. This flaw allows a remote attacker to execute a script in a victim's Web browser within the security context of the hosting Web site, which can lead to stealing the victim's cookie-based authentication credentials.
Red Hat Decision Manager is an open source decision management platform that combines business rules management, complex event processing, Decision Model & Notation execution, and Business Optimizer for solving planning problems. It automates business decisions and makes that logic available to the entire business. This release of Red Hat Decision Manager 7.6.0 serves as an update to Red Hat Decision Manager 7.5.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-07 First Exploit
- 2019-01-08 CVE Reserved
- 2019-01-09 CVE Published
- 2024-08-05 CVE Updated
- 2025-05-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (17)
URL | Date | SRC |
---|---|---|
https://github.com/ossf-cve-benchmark/CVE-2018-20677 | 2018-05-07 | |
https://github.com/twbs/bootstrap/issues/27045 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/twbs/bootstrap/pull/27047 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHBA-2019:1076 | 2023-11-07 | |
https://access.redhat.com/errata/RHBA-2019:1570 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2019:1456 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2019:3023 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2020:0132 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2020:0133 | 2023-11-07 | |
https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2018-20677 | 2023-10-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1668089 | 2023-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Getbootstrap Search vendor "Getbootstrap" | Bootstrap Search vendor "Getbootstrap" for product "Bootstrap" | < 3.4.0 Search vendor "Getbootstrap" for product "Bootstrap" and version " < 3.4.0" | - |
Affected
|