In Bootstrap prima 4.1.2, XSS è possibile nell’attributo collasso dei dati-genitore. |
https://seclists.org/bugtraq/2019/May/18 http://seclists.org/fulldisclosure/2019/May/13 http://seclists.org/fulldisclosure/2019/May/11 http://seclists.org/fulldisclosure/2019/May/10 http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html https://blog.getbootstrap.com/2018/07/12/bootstrap-4-1-2/ https://github.com/twbs/bootstrap/issues/26423 https://github.com/twbs/bootstrap/issues/26625 https://github.com/twbs/bootstrap/pull/26630 https://lists.debian.org/debian-lts-announce/2018/08/msg00027.html https://lists.apache.org/thread.html/[email protected]%3Cdev.drill.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Cdev.drill.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Cissues.drill.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Cissues.hbase.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Ccommits.pulsar.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Cdev.superset.apache.org%3E https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14040 |
Vulnerabilità: CVE-2018-14040
