[Bug 1940450] Re: XSS The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
Heather Lemon
1940450 at bugs.launchpad.net
Wed Sep 1 15:13:07 UTC 2021
Attached screenshot showing difference between Bootstrap versions with
missing sanitize functions
** Attachment added: "Screenshot from 2021-08-23 15-55-14.png"
https://bugs.launchpad.net/horizon/+bug/1940450/+attachment/5522304/+files/Screenshot%20from%202021-08-23%2015-55-14.png
--
You received this bug notification because you are a member of Ubuntu
OpenStack, which is subscribed to horizon in Ubuntu.
https://bugs.launchpad.net/bugs/1940450
Title:
XSS The data-template attribute of the tooltip and popover plugins
lacks input sanitization and may allow attacker to execute arbitrary
JavaScript.
Status in Ubuntu Cloud Archive:
New
Status in OpenStack Dashboard (Horizon):
Invalid
Status in OpenStack Security Advisory:
Invalid
Status in horizon package in Ubuntu:
New
Status in python-xstatic-bootstrap-scss package in Ubuntu:
New
Bug description:
The data-template attribute of the tooltip and popover plugins lacks
input sanitization and may allow attacker to execute arbitrary
JavaScript.
github source: https://github.com/twbs/bootstrap/pull/28236
github upstream MR: https://github.com/twbs/bootstrap/pull/28236/commits/5efa9b531d25927b907e3fa24b818608bc38a2f0
ubuntu-cve https://ubuntu.com/security/CVE-2019-8331
openstack-dashboard,from xenial UCA, python-django-horizon version 13.0.2-0ubuntu3~cloud0
`pull-uca-source python-django-horizon 3:13.0.2-0ubuntu3~cloud0`
To manage notifications about this bug go to:
https://bugs.launchpad.net/cloud-archive/+bug/1940450/+subscriptions
More information about the Ubuntu-openstack-bugs
mailing list