Cross-site scripting in Bootstrap - CVE-2018-20676

 

Cross-site scripting in Bootstrap - CVE-2018-20676

Published: January 13, 2019


Vulnerability identifier: #VU16956
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2018-20676
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists in the tooltip data-viewport attribute due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Bootstrap
watsonx.data
EcoWebServerIII MES3-255C-EN
EcoWebServerIII MES3-255C-DM-CN
EcoWebServerIII MES3-255C-DM-EN
EcoWebServerIII MES3-255C-CN
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Aspera Orchestrator
QRadar User Behavior Analytics
Engineering Workflow Management
IBM Maximo Asset Management
IBM Security Verify Governance
Ceph
IBM Business Automation Workflow
Cloud Pak for Network Automation
Storage Ceph
MobileFirst Platform
ipa (Red Hat package)
cephadm-ansible (Red Hat package)
python-XStatic-Bootstrap-SCSS (Red Hat package)
IBM Edge Application Manager
Red Hat Virtualization Manager
Tenable.sc
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Storage Scale System

How to mitigate CVE-2018-20676

Update to version 3.4.0.

Bootstrap - addressed in versions 3.4.0, 4.0.0 beta.2
EcoWebServerIII MES3-255C-EN - update to 3.3.1
EcoWebServerIII MES3-255C-DM-CN - update to 3.3.1
EcoWebServerIII MES3-255C-DM-EN - update to 3.3.1
EcoWebServerIII MES3-255C-CN - update to 3.3.1
Cloud Pak for Network Automation - update to 2.7.2
ipa (Red Hat package) - update to 4.6.8-5.el7
Tenable.sc - update to 5.19.0
watsonx.data - update to 2.1.1
cephadm-ansible (Red Hat package) - update to 3.0.0-1.el9cp
python-XStatic-Bootstrap-SCSS (Red Hat package) - update to 3.4.1.0-1.el7ost
IBM Aspera Orchestrator - update to 4.0.1 PL2
QRadar User Behavior Analytics - update to 4.1.17
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
IBM Storage Scale System - addressed in versions 5.1.9.5, 5.2.0.0
Storage Ceph - update to 6.1z2
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
IBM Maximo Asset Management - update to 7.6.1.2.0.31
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202304111626
IBM Security Verify Governance - update to 10.0.2.0.1
Ceph - update to 17.2.6-148.el9cp
IBM Business Automation Workflow - addressed in versions 21.0.3 IF019, 22.0.2 IF003

External References

Related Security Bulletins