Red Hat Bugzilla – Bug 1601614
CVE-2018-14040 bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
Last modified: 2018-10-26 16:20:20 EDT
A flaw was found in Bootstrap from version 4.0 and before 4.1.2. A Cross-site Scripting (XSS) is possible in the collapse data-parent attribute. References: https://github.com/twbs/bootstrap/issues/26625 Upstream Patch: https://github.com/twbs/bootstrap/pull/26630
bootstrap 3.3.7 is affected by this flaw.