CVE-2018-14041: XSS
A flaw was found in Bootstrap from version 4.0 and before 4.1.2. A Cross-site Scripting (XSS) is possible in the data-target property of scrollspy.
References: https://github.com/twbs/bootstrap/issues/26627
Upstream Patch: https://github.com/twbs/bootstrap/pull/26630
Other sources
A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting, caused by improper validation of user-supplied input by the data-target property of scrollspy. This flaw allows a remote attacker to execute a script in a victim's Web browser within the security context of the hosting Web site, which can lead to stealing the victim's cookie-based authentication credentials.
Bootstrap is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the data-target property of scrollspy. A remote attacker could exploit this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
— IBM
Cross-Site Scripting in Bootstrap CSS toolkit
In Bootstrap 4.x before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042.
— GitHub
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/eap7-hal-consoleto a version that resolves this vulnerability.Fixed in 0:3.3.16-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-hal-consoleto a version that resolves this vulnerability.Fixed in 0:3.3.16-1.Final_redhat_00001.1.el9ea - Upgrade
Upgrade
redhat/eap7-hal-consoleto a version that resolves this vulnerability.Fixed in 0:3.3.16-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
maven/org.webjars:bootstrapto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
nuget/bootstrap.sassto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
nuget/bootstrapto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
composer/twbs/bootstrapto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
rubygems/bootstrapto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 9.5.4 - Upgrade
Upgrade
composer/typo3/cmsto a version that resolves this vulnerability.Fixed in 8.7.23 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 9.5.4 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 8.7.23 - Upgrade
Upgrade
npm/bootstrapto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
redhat/bootstrapto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
Bootstrapto a version that resolves this vulnerability.Fixed in 4.1.2 - Compensating control
If you cannot immediately upgrade, mitigate the risk by preventing untrusted user input from being used in the scrollspy data-target attribute (e.g., ensure data-target values are fixed/whitelisted and not derived from attacker-controlled input).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this cross-site scripting vulnerability in Bootstrap CSS toolkit?
The vulnerability ID is CVE-2018-14041.
What is the severity of CVE-2018-14041?
The severity of CVE-2018-14041 is medium (6.1).
Which software versions are affected by CVE-2018-14041?
The affected software versions are TYPO3 CMS versions 8.0.0 to 8.7.23 and 9.0.0 to 9.5.4, and Red Hat EAP7 HAL Console versions 0:3.3.16-1.Final_redhat_00001.1.el8ea, 0:3.3.16-1.Final_redhat_00001.1.el9ea, and 0:3.3.16-1.Final_redhat_00001.1.el7ea.
How does this vulnerability in Bootstrap CSS toolkit affect the user?
This vulnerability allows a remote attacker to execute scripts in a victim's web browser within the security context of the hosting website.
How can I mitigate the cross-site scripting vulnerability in Bootstrap CSS toolkit?
To mitigate this vulnerability, update to TYPO3 CMS versions 8.7.24 or 9.5.5, or apply the appropriate patch provided by Red Hat for EAP7 HAL Console.