Red Hat Bugzilla – Bug 1601616
CVE-2018-14041 bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy
Last modified: 2018-10-15 01:25:23 EDT
A flaw was found in Bootstrap from version 4.0 and before 4.1.2. A Cross-site Scripting (XSS) is possible in the data-target property of scrollspy. References: https://github.com/twbs/bootstrap/issues/26627 Upstream Patch: https://github.com/twbs/bootstrap/pull/26630
bootstrap 3.3.7 is not affected by this flaw.