PT-2019-5302 · Twitter+4 · Bootstrap+4

Published

2019-02-20

·

Updated

2025-11-30

·

CVE-2019-8331

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bootstrap versions prior to 3.4.1 for 3.x and 4.3.1 for 4.x
Description The issue is related to Cross-Site Scripting (XSS) in the tooltip or popover data-template attribute of the Bootstrap toolkit. This is due to a lack of input sanitization, which may allow an attacker to execute arbitrary JavaScript. The vulnerability can be exploited by a remote attacker to perform cross-site scripting attacks.
Recommendations For Bootstrap 4.x, upgrade to 4.3.1 or later. For Bootstrap 3.x, upgrade to 3.4.1 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALSA-2020:4670
ALSA-2025_16880
BDU:2020-02249
CESA-2020_3936
CESA-2020_4670
CESA-2020_4847
CVE-2019-8331
GHSA-9V3M-8FP8-MJ99
RHSA-2019:3023
RHSA-2019:3024
RHSA-2020:3247
RHSA-2020:3936
RHSA-2020:4670
RHSA-2020:4847
RHSA-2020:5571
RHSA-2020_3936
RHSA-2020_4670
RHSA-2020_4847
RHSA-2022:8848
RHSA-2022:8865
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
RLSA-2020:4670
RLSA-2020:4847

Affected Products

Almalinux
Bootstrap
Centos
Red Hat
Rocky Linux