UBUNTU-CVE-2016-10735
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-10735
Summary:
Details: In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
References: https://ubuntu.com/security/CVE-2016-10735, https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/, https://github.com/twbs/bootstrap/issues/20184, https://github.com/twbs/bootstrap/issues/27915#issuecomment-452140906, https://github.com/twbs/bootstrap/pull/23679, https://github.com/twbs/bootstrap/pull/23687, https://github.com/twbs/bootstrap/pull/26460, https://www.cve.org/CVERecord?id=CVE-2016-10735
Affected packages
Package
Name: twitter-bootstrap3
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
