PT-2018-12296 · Twitter+4 · Bootstrap+4

Published

2018-07-13

·

Updated

2025-12-07

·

CVE-2018-14042

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bootstrap versions 2.3.0 through 4.1.1
Description The issue allows for XSS in the data-container property of tooltip. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For Bootstrap versions 2.3.0 through 3.3.x, update to version 3.4.0 or later. For Bootstrap versions 3.4.0 through 4.1.1, update to version 4.1.2 or later. As a temporary workaround, consider disabling the use of the data-container property in the tooltip until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALSA-2020:4670
ALSA-2025_16880
AZL-44094
CESA-2020_3936
CESA-2020_4670
CESA-2020_4847
CVE-2018-14042
GHSA-7MVR-5X2G-WFC8
RHSA-2020:3936
RHSA-2020:4670
RHSA-2020:4847
RHSA-2020:5571
RHSA-2020_3936
RHSA-2020_4670
RHSA-2020_4847
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
RHSA-2023:1043
RHSA-2023:1044
RHSA-2023:1045
RLSA-2020:4670
RLSA-2020:4847

Affected Products

Almalinux
Bootstrap
Centos
Red Hat
Rocky Linux