In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
CVE-2016-10735 - Medium Severity Vulnerability
Vulnerable Library - r-rmarkdown-2.11-r40hc72bb7e_1.tar.bz2
Convert R Markdown documents into a variety of formats.
Library home page: https://api.anaconda.org/download/conda-forge/r-rmarkdown/2.11/noarch/r-rmarkdown-2.11-r40hc72bb7e_1.tar.bz2
Path to dependency file: /containers/report/environment.yml
Path to vulnerable library: /home/wss-scanner/anaconda3/pkgs/r-rmarkdown-2.11-r40hc72bb7e_1.tar.bz2
Dependency Hierarchy: - r-kableextra-1.3.4-r40hc72bb7e_0.tar.bz2 (Root Library) - :x: **r-rmarkdown-2.11-r40hc72bb7e_1.tar.bz2** (Vulnerable Library)
Found in base branch: main
Vulnerability Details
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
Publish Date: 2019-01-09
URL: CVE-2016-10735
CVSS 3 Score Details (6.1)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10735
Release Date: 2019-01-09
Fix Resolution: bootstrap - 3.4.0, 4.0.0-beta.2
Step up your Open Source Security Game with WhiteSource here