bsbtd / Teste

0 stars 1 forks source link

CVE-2018-14040 (Medium) detected in bootstrap-3.2.0.min.js, r-rmarkdown-2.8-r36hc72bb7e_0.tar.bz2 - autoclosed #772

Closed mend-bolt-for-github[bot] closed 2 years ago

mend-bolt-for-github[bot] commented 3 years ago

CVE-2018-14040 - Medium Severity Vulnerability

Vulnerable Libraries - bootstrap-3.2.0.min.js, r-rmarkdown-2.8-r36hc72bb7e_0.tar.bz2

bootstrap-3.2.0.min.js

The most popular front-end framework for developing responsive, mobile first projects on the web.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js

Path to vulnerable library: /n.js

Dependency Hierarchy: - :x: **bootstrap-3.2.0.min.js** (Vulnerable Library)

r-rmarkdown-2.8-r36hc72bb7e_0.tar.bz2

Convert R Markdown documents into a variety of formats.

Library home page: https://api.anaconda.org/download/conda-forge/r-rmarkdown/2.8/noarch/r-rmarkdown-2.8-r36hc72bb7e_0.tar.bz2

Path to dependency file: /proteomicslfq/environment.yml

Path to vulnerable library: /home/wss-scanner/anaconda3/pkgs/r-rmarkdown-2.8-r36hc72bb7e_0.tar.bz2

Dependency Hierarchy: - r-ptxqc-1.0.2-r36h6115d3f_0.tar.bz2 (Root Library) - :x: **r-rmarkdown-2.8-r36hc72bb7e_0.tar.bz2** (Vulnerable Library)

Found in HEAD commit: 64dde89c50c07496423c4d4a865f2e16b92399ad

Vulnerability Details

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

Publish Date: 2018-07-13

URL: CVE-2018-14040

CVSS 3 Score Details (6.1)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/twbs/bootstrap/pull/26630

Release Date: 2018-07-13

Fix Resolution: org.webjars.npm:bootstrap:4.1.2,org.webjars:bootstrap:3.4.0


Step up your Open Source Security Game with WhiteSource here

mend-bolt-for-github[bot] commented 2 years ago

:heavy_check_mark: This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.