CVE-2024-6485
twitter-bootstrap3 - security update
6.4
MEDIUM
CVSS 3.1
EPSS 0.14%
Description
A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.
How to fix CVE-2024-6485
To remediate CVE-2024-6485, upgrade the affected package to a fixed version below.
- —upgrade to 3.4.1+dfsg-2+deb11u1 or later
- —upgrade to 3.4.1+dfsg-2+deb11u1 or later
- —no fix listed
Is CVE-2024-6485 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 3.4.1+dfsg-2+deb11u1
- from 0, < 3.4.1+dfsg-2+deb11u1
- >= 1.4.0, <= 3.4.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L |