Skip to content

Update dependency bootstrap to 3.4.1 [SECURITY] - abandoned#3

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-bootstrap-vulnerability
Open

Update dependency bootstrap to 3.4.1 [SECURITY] - abandoned#3
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-bootstrap-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented Aug 28, 2019

Mend Renovate

This PR contains the following updates:

Package Change
bootstrap 3.3.6 -> 3.4.1

GitHub Vulnerability Alerts

CVE-2018-14041

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. This is similar to CVE-2018-14042.

CVE-2016-10735

In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute. Note that this is a different vulnerability than CVE-2018-14041.

See https://blog.getbootstrap.com/2018/12/13/bootstrap-3-4-0/ for more info.

CVE-2018-20677

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

CVE-2018-20676

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

CVE-2019-8331

In Bootstrap 4 before 4.3.1 and Bootstrap 3 before 3.4.1, XSS is possible in the tooltip or popover data-template attribute. For more information, see: https://blog.getbootstrap.com/2019/02/13/bootstrap-4-3-1-and-3-4-1/

CVE-2019-8331

Versions of bootstrap prior to 3.4.1 for 3.x and 4.3.1 for 4.x are vulnerable to Cross-Site Scripting (XSS). The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.

Recommendation

For bootstrap 4.x upgrade to 4.3.1 or later.
For bootstrap 3.x upgrade to 3.4.1 or later.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-bootstrap-vulnerability branch from ba88223 to b9d04a9 Compare August 28, 2019 17:15
@renovate renovate bot changed the title Update dependency bootstrap to v3.4.1 [SECURITY] Update dependency bootstrap to 3.4.1 [SECURITY] Apr 26, 2021
@renovate
Copy link
Copy Markdown
Author

renovate bot commented Mar 24, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@renovate renovate bot changed the title Update dependency bootstrap to 3.4.1 [SECURITY] Update dependency bootstrap to 3.4.1 [SECURITY] - abandoned Nov 5, 2023
@renovate
Copy link
Copy Markdown
Author

renovate bot commented Nov 5, 2023

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant