Skip to content

fix: Solve XSS vulnerability (CVE-2025-1647)#11

Open
martijnpieters wants to merge 1 commit intoentreprise7pro:v3-devfrom
martijnpieters:v3-dev
Open

fix: Solve XSS vulnerability (CVE-2025-1647)#11
martijnpieters wants to merge 1 commit intoentreprise7pro:v3-devfrom
martijnpieters:v3-dev

Conversation

@martijnpieters
Copy link

This fix was made by the Debian people, not by me. So credits to them.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS)

DOM-based cross-site scripting (XSS) via DOM clobbering occurs when an attacker manipulates the Document Object Model (DOM) to overwrite or "clobber" an existing DOM object, leading to the execution of malicious scripts.

document.implementation should be tested against well known type

Use DOMParser if possible (supported since 2015) in order to create a DoS in case of document.implementation overriden.

See: #1
See: https://www.herodevs.com/vulnerability-directory/cve-2025-1647
See: https://salsa.debian.org/js-team/twitter-bootstrap3/-/blob/master/debian/patches/CVE-2025-1647.patch?ref_type=heads

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability
in Bootstrap allows Cross-Site Scripting (XSS)

DOM-based cross-site scripting (XSS) via DOM clobbering occurs when an attacker
manipulates the Document Object Model (DOM) to overwrite
or "clobber" an existing DOM object, leading to the execution
of malicious scripts.

document.implementation should be tested against well known type

Use DOMParser if possible (supported since 2015) in order to create a DoS in case
of document.implementation overriden.

See: https://www.herodevs.com/vulnerability-directory/cve-2025-1647
See: https://salsa.debian.org/js-team/twitter-bootstrap3/-/blob/master/debian/patches/CVE-2025-1647.patch?ref_type=heads
@rhoehmann
Copy link

Is there any chance that this merge request will be approved and lead to a new fix version of this library? I would be very happy about that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants