CVE-2018-20677: XSS
A flaw was found in Bootstrap before 3.4.0. XSS is possible in the affix configuration target property.
References: https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ https://github.com/twbs/bootstrap/issues/27045 https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906 https://github.com/twbs/bootstrap/issues/27915#issuecomment-452196628
Upstream Patch: https://github.com/twbs/bootstrap/pull/27047
Other sources
A flaw was found in Bootstrap, where it is vulnerable to Cross-site scripting caused by improper validation of user-supplied input by the affix configuration target property. This flaw allows a remote attacker to execute a script in a victim's Web browser within the security context of the hosting Web site, which can lead to stealing the victim's cookie-based authentication credentials.
Bootstrap is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the affix configuration target property. A remote attacker could exploit this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
— IBM
In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2018-20677?
CVE-2018-20677 is a vulnerability in Bootstrap before 3.4.0 that allows for cross-site scripting (XSS) attacks.
What is the severity of CVE-2018-20677?
The severity of CVE-2018-20677 is medium with a CVSS score of 6.1.
How can an attacker exploit CVE-2018-20677?
An attacker can exploit CVE-2018-20677 by injecting malicious scripts into a victim's web browser through the affix configuration target property.
Is there a fix for CVE-2018-20677?
Yes, updating Bootstrap to version 3.4.0 or above will fix the vulnerability.
Where can I find more information about CVE-2018-20677?
You can find more information about CVE-2018-20677 at the following links: [CVE-2018-20677](https://www.cve.org/CVERecord?id=CVE-2018-20677), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-20677), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1668089), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2020:0133).