tempusdominus / bootstrap-3

Tempus Dominus Bootstrap 3
https://getdatepicker.com/5-3/
MIT License
70 stars 23 forks source link

Dependency vulnerability with Boostrap 3.3.7 #126

Open JohnMica opened 4 years ago

JohnMica commented 4 years ago

Vulnerable module: bootstrap Introduced through: eonasdan-bootstrap-datetimepicker@4.17.47 Exploit maturity: No known exploit Fixed in: 3.4.0, 4.0.0-beta.2

....

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) via the data-target attribute.
...

just thought you could upgrade the dependencies perhaps ? not sure what other impact this would have, but hopefully none