CVE-2018-20676

Aliases:GHSA-3mgp-fx93-9xv5DEBIAN-CVE-2018-20676CGA-3xq2-6mv3-chx3CGA-62cv-34gw-xf76CGA-6q2w-mpg3-wp4gCGA-7jh7-v7wc-h4qhCGA-9cq9-v3m3-jwv5CGA-9wr6-8fxj-mp7jCGA-c8qf-5vfh-7jhvCGA-fjqc-j435-cq9fCGA-g9q7-cvvm-wv82CGA-gjx9-92qm-h4v6CGA-m5hv-87qj-grgxCGA-w38p-65q7-748gCGA-w8xg-wqm2-jpxcCGA-wm99-6gf8-4c25
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 09 Jan 2019, 05:00
Last modified:05 Aug 2024, 12:05

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.1 MEDIUM
v3.0 (nvd)
EPSS Score
3.84% LOW
4% probability -2.31%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jan 2019, 05:00
Published
Vulnerability first disclosed
05 Aug 2024, 12:05
Last Modified
Vulnerability information updated

Description

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

CVSS Metrics

  • v3.0MEDIUMScore: 6.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 3.84% Percentile: 90%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • chainguardgrafana-11.3

    < 11.3.9-r5

  • chainguardgrafana-11.4

    < 11.4.8-r2

  • chainguardgrafana-11.5

    < 11.5.10-r0

  • chainguardgrafana-11.6

    < 11.6.7-r0

  • chainguardgrafana-fips-11.4

    < 11.4.8-r2

  • chainguardgrafana-fips-11.5

    < 11.5.10-r0

  • chainguardgrafana-fips-11.6

    < 11.6.7-r0

  • twbsbootstrap

    < 3.4.0

  • debiantwitter-bootstrap3

    < 3.4.0+dfsg-1 | < 3.4.0+dfsg-1 | < 3.4.0+dfsg-1 | < 3.4.0+dfsg-1

  • RubyGemsbootstrap

    < 3.4.0

  • RubyGemsbootstrap-sass

    < 3.4.0

  • getbootstrapbootstrap

    < 3.4.0

  • org.webjarsbootstrap

    < 3.4.0

  • Npmbootstrap

    < 3.4.0

  • Npmbootstrap-sass

    < 3.4.0

  • NuGetbootstrap

    < 3.4.0

References (21)