Closed r-brown closed 5 years ago
Known vulnerability found CVE-2018-14041 Moderate severity
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042. package.json update suggested: bootstrap ~> 4.1.2
Upgrading to Bootstrap 3.4.1 should fix this.
3.4.1
Known vulnerability found CVE-2018-14041 Moderate severity
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042. package.json update suggested: bootstrap ~> 4.1.2