Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2019-8331

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
getbootstrap / bootstrap - 3.4.1
getbootstrap / bootstrap 4.3.0 4.3.1
f5 / big-ip_local_traffic_manager 15.0.0 15.1.0
f5 / big-ip_application_security_manager 15.0.0 15.1.0
f5 / big-ip_access_policy_manager 15.0.0 15.1.0
f5 / big-ip_advanced_firewall_manager 15.0.0 15.1.0
f5 / big-ip_analytics 15.0.0 15.1.0
f5 / big-ip_application_acceleration_manager 15.0.0 15.1.0
f5 / big-ip_domain_name_system 15.0.0 15.1.0
f5 / big-ip_fraud_protection_service 15.0.0 15.1.0
f5 / big-ip_global_traffic_manager 15.0.0 15.1.0
f5 / big-ip_link_controller 15.0.0 15.1.0
f5 / big-ip_policy_enforcement_manager 15.0.0 15.1.0
f5 / big-ip_webaccelerator 15.0.0 15.1.0
f5 / big-ip_edge_gateway 15.0.0 15.1.0
f5 / big-ip_access_policy_manager 12.1.0 12.1.5.1
f5 / big-ip_analytics 12.1.0 12.1.5.1
f5 / big-ip_advanced_firewall_manager 12.1.0 12.1.5.1
f5 / big-ip_application_acceleration_manager 12.1.0 12.1.5.1
f5 / big-ip_local_traffic_manager 12.1.0 12.1.5.1
f5 / big-ip_application_security_manager 12.1.0 12.1.5.1
f5 / big-ip_webaccelerator 12.1.0 12.1.5.1
f5 / big-ip_policy_enforcement_manager 12.1.0 12.1.5.1
f5 / big-ip_link_controller 12.1.0 12.1.5.1
f5 / big-ip_global_traffic_manager 12.1.0 12.1.5.1
f5 / big-ip_fraud_protection_service 12.1.0 12.1.5.1
f5 / big-ip_edge_gateway 12.1.0 12.1.5.1
f5 / big-ip_domain_name_system 12.1.0 12.1.5.1
f5 / big-ip_local_traffic_manager 14.0.0 14.1.2.5
f5 / big-ip_application_acceleration_manager 14.0.0 14.1.2.5
f5 / big-ip_advanced_firewall_manager 14.0.0 14.1.2.5
f5 / big-ip_analytics 14.0.0 14.1.2.5
f5 / big-ip_access_policy_manager 14.0.0 14.1.2.5
f5 / big-ip_application_security_manager 14.0.0 14.1.2.5
f5 / big-ip_domain_name_system 14.0.0 14.1.2.5
f5 / big-ip_fraud_protection_service 14.0.0 14.1.2.5
f5 / big-ip_global_traffic_manager 14.0.0 14.1.2.5
f5 / big-ip_link_controller 14.0.0 14.1.2.5
f5 / big-ip_policy_enforcement_manager 14.0.0 14.1.2.5
f5 / big-ip_access_policy_manager 13.0.0 13.1.3.4
f5 / big-ip_advanced_firewall_manager 13.0.0 13.1.3.4
f5 / big-ip_analytics 13.0.0 13.1.3.4
f5 / big-ip_application_acceleration_manager 13.0.0 13.1.3.4
f5 / big-ip_application_security_manager 13.0.0 13.1.3.4
f5 / big-ip_domain_name_system 13.0.0 13.1.3.4
f5 / big-ip_edge_gateway 13.0.0 13.1.3.4
f5 / big-ip_edge_gateway 14.0.0 14.1.2.5
f5 / big-ip_fraud_protection_service 13.0.0 13.1.3.4
f5 / big-ip_global_traffic_manager 13.0.0 13.1.3.4
f5 / big-ip_link_controller 13.0.0 13.1.3.4
f5 / big-ip_local_traffic_manager 13.0.0 13.1.3.4
f5 / big-ip_policy_enforcement_manager 13.0.0 13.1.3.4
f5 / big-ip_webaccelerator 13.0.0 13.1.3.4
f5 / big-ip_webaccelerator 14.0.0 14.1.2.5
redhat / virtualization_manager 4.3 4.3.x
tenable / tenable.sc - 5.19.0
bootstrap - 4.3.1
bootstrap-sass 3.0.0 3.4.1
Bootstrap.Less 3.0.0 3.4.1
bootstrap 4.0.0 4.3.1
bootstrap 3.0.0 3.4.1
bootstrap.sass - 4.3.1
@lerna / bootstrap 4.0.0 4.3.1
@lerna / bootstrap 3.0.0 3.4.1
bootstrap-sass 3.0.0 3.4.1