{"id":"GHSA-c7pp-x73h-4m2v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-c7pp-x73h-4m2v","summary":"Cross-Site Scripting in bootstrap-vue","details":"Versions of `bootstrap-vue` prior to 2.0.0-rc.12 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization, components may be vulnerable to Cross-Site Scripting through the `options` variable. This may lead to the execution of malicious JavaScript on the user's browser.\n\n\n## Recommendation\n\nUpgrade to version 2.0.0-rc.12 or later.","published":"2020-09-02T15:53:46Z","modified":"2021-09-27T15:43:19Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"bootstrap-vue","fixedVersion":"2.0.0-rc.12"}],"fix":{"url":"https://github.com/bootstrap-vue/bootstrap-vue/pull/2134","label":"bootstrap-vue/bootstrap-vue#2134"},"references":[{"type":"WEB","url":"https://github.com/bootstrap-vue/bootstrap-vue/issues/1974"},{"type":"WEB","url":"https://github.com/bootstrap-vue/bootstrap-vue/pull/2134"},{"type":"WEB","url":"https://github.com/bootstrap-vue/bootstrap-vue/commit/ba6f3f8359e257589d744f180312c09bf9f12289"},{"type":"PACKAGE","url":"https://github.com/bootstrap-vue/bootstrap-vue"},{"type":"WEB","url":"https://www.npmjs.com/advisories/770"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-27T15:43:19Z"}}