Cross-site scripting in Bootstrap - CVE-2018-20677
Published: December 14, 2018 / Updated: January 13, 2019
Vulnerability details
The vulnerability exists in the affix configuration target property due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
watsonx.data
Cloud Pak for Network Automation
Storage Defender – Data Protect
Storage Ceph
MobileFirst Platform
ipa (Red Hat package)
cephadm-ansible (Red Hat package)
python-XStatic-Bootstrap-SCSS (Red Hat package)
IBM Edge Application Manager
Red Hat Virtualization Manager
Tenable.sc
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Aspera Orchestrator
QRadar User Behavior Analytics
Engineering Workflow Management
IBM Maximo Asset Management
IBM Security Verify Governance
Ceph
IBM Business Automation Workflow
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Storage Scale System
How to mitigate CVE-2018-20677
Cloud Pak for Network Automation - update to 2.7.2
ipa (Red Hat package) - update to 4.6.8-5.el7
Tenable.sc - update to 5.19.0
Storage Defender – Data Protect - update to 2.0
watsonx.data - update to 2.1.1
cephadm-ansible (Red Hat package) - update to 3.0.0-1.el9cp
python-XStatic-Bootstrap-SCSS (Red Hat package) - update to 3.4.1.0-1.el7ost
IBM Aspera Orchestrator - update to 4.0.1 PL2
QRadar User Behavior Analytics - update to 4.1.17
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
IBM Storage Scale System - addressed in versions 5.1.9.5, 5.2.0.0
Storage Ceph - update to 6.1z2
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
IBM Maximo Asset Management - update to 7.6.1.2.0.31
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202304111626
IBM Security Verify Governance - update to 10.0.2.0.1
Ceph - update to 17.2.6-148.el9cp
IBM Business Automation Workflow - addressed in versions 21.0.3 IF019, 22.0.2 IF003
External References
Related Security Bulletins
- Cross-site scripting in Bootstrap
- Red Hat update for ovirt-engine-ui-extensions
- Red Hat Enterprise Linux 7 update for ipa
- Red Hat Enterprise Linux 8 update for the idm:DL1 and idm:client modules
- Red Hat OpenStack update for python-XStatic-Bootstrap-SCSS
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in IBM Maximo Asset Management
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in Red Hat Ceph Storage 6.1
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.14
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM Security Verify Governance
- Cross-site scripting in IBM Storage Ceph
- Multiple vulnerabilities in IBM Aspera Orchestrator
- Multiple vulnerabilities in IBM MobileFirst Platform Foundation
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Storage Scale
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM watsonx.data