Cross-site scripting in Bootstrap - CVE-2018-20677

 

Cross-site scripting in Bootstrap - CVE-2018-20677

Published: December 14, 2018 / Updated: January 13, 2019


Vulnerability identifier: #VU16542
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2018-20677
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists in the affix configuration target property due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Bootstrap
watsonx.data
Cloud Pak for Network Automation
Storage Defender – Data Protect
Storage Ceph
MobileFirst Platform
ipa (Red Hat package)
cephadm-ansible (Red Hat package)
python-XStatic-Bootstrap-SCSS (Red Hat package)
IBM Edge Application Manager
Red Hat Virtualization Manager
Tenable.sc
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Aspera Orchestrator
QRadar User Behavior Analytics
Engineering Workflow Management
IBM Maximo Asset Management
IBM Security Verify Governance
Ceph
IBM Business Automation Workflow
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Storage Scale System

How to mitigate CVE-2018-20677

Update to version 3.4.0.

Bootstrap - addressed in versions 3.4.0, 4.0.0 beta.2
Cloud Pak for Network Automation - update to 2.7.2
ipa (Red Hat package) - update to 4.6.8-5.el7
Tenable.sc - update to 5.19.0
Storage Defender – Data Protect - update to 2.0
watsonx.data - update to 2.1.1
cephadm-ansible (Red Hat package) - update to 3.0.0-1.el9cp
python-XStatic-Bootstrap-SCSS (Red Hat package) - update to 3.4.1.0-1.el7ost
IBM Aspera Orchestrator - update to 4.0.1 PL2
QRadar User Behavior Analytics - update to 4.1.17
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
IBM Storage Scale System - addressed in versions 5.1.9.5, 5.2.0.0
Storage Ceph - update to 6.1z2
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
IBM Maximo Asset Management - update to 7.6.1.2.0.31
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202304111626
IBM Security Verify Governance - update to 10.0.2.0.1
Ceph - update to 17.2.6-148.el9cp
IBM Business Automation Workflow - addressed in versions 21.0.3 IF019, 22.0.2 IF003

External References

Related Security Bulletins