---
title: "CVE-2018-20676"
canonical: "https://kb.cynergy.app/space/MD/899285418/CVE-2018-20676"
format: markdown
---
**Description:**

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

**Published On:**

2018-08-10

**Updated On:**

2021-07-22

**Trending:**

FALSE

**CWE:**

CWE-79

**Mitigation:**

![image](media://903f52b3-13b8-4e6f-9b65-a55e58fa81de)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| RHSA-2020:3936 | OpenSource | ipa-4.6.8-5.el7 | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:3936](https://access.redhat.com/errata/RHSA-2020:3936) |
| RHSA-2020:4670 | OpenSource | bind-dyndb-ldap-11.3-1.module+el8.3.0+6993+104f8db0 | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:4670](https://access.redhat.com/errata/RHSA-2020:4670) |
| RHBA-2019:1076 | redhat | Red Hat Bug Fix Advisory: ovirt-engine-api-explorer bug fix and enhancement update for RHV 4.3 | Updated ovirt-engine-api-explorer packages that fix several bugs and add various enhancements are now available. | 2019-08-19 | [https://access.redhat.com/errata/RHBA-2019:1076](https://access.redhat.com/errata/RHBA-2019:1076) |
| RHBA-2019:1570 | redhat | Red Hat Bug Fix Advisory: ovirt-engine-api-explorer bug fix and enhancement update for RHV 4.3.4 | Updated ovirt-engine-api-explorer packages that fix several bugs and add various enhancements are now available. | 2019-08-19 | [https://access.redhat.com/errata/RHBA-2019:1570](https://access.redhat.com/errata/RHBA-2019:1570) |
| RHSA-2019:1456 | redhat | Red Hat Security Advisory: Red Hat Single Sign-On 7.3.2 security update | A security update is now available for Red Hat Single Sign-On 7.3 from the Customer Portal.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-06-12 | [https://access.redhat.com/errata/RHSA-2019:1456](https://access.redhat.com/errata/RHSA-2019:1456) |
| RHSA-2019:3023 | redhat | Red Hat Security Advisory: ovirt-engine-ui-extensions security and bug fix update | An update for ovirt-engine-ui-extensions is now available for Red Hat Virtualization Engine 4.3.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-11 | [https://access.redhat.com/errata/RHSA-2019:3023](https://access.redhat.com/errata/RHSA-2019:3023) |
| RHSA-2020:0132 | redhat | Red Hat Security Advisory: Red Hat Process Automation Manager 7.6.0 Security Update | An update is now available for Red Hat Process Automation Manager.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-01-17 | [https://access.redhat.com/errata/RHSA-2020:0132](https://access.redhat.com/errata/RHSA-2020:0132) |
| RHSA-2020:0133 | redhat | Red Hat Security Advisory: Red Hat Decision Manager 7.6.0 Security Update | An update is now available for Red Hat Decision Manager.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-01-17 | [https://access.redhat.com/errata/RHSA-2020:0133](https://access.redhat.com/errata/RHSA-2020:0133) |
| RHSA-2020:3936 | redhat | Red Hat Security Advisory: ipa security, bug fix, and enhancement update | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-13 | [https://access.redhat.com/errata/RHSA-2020:3936](https://access.redhat.com/errata/RHSA-2020:3936) |
| RHSA-2020:4670 | redhat | Red Hat Security Advisory: idm:DL1 and idm:client security, bug fix, and enhancement update | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-11-05 | [https://access.redhat.com/errata/RHSA-2020:4670](https://access.redhat.com/errata/RHSA-2020:4670) |
| RHSA-2020:5571 | redhat | Red Hat Security Advisory: python-XStatic-Bootstrap-SCSS security update | An update for python-XStatic-Bootstrap-SCSS is now available for Red Hat  
OpenStack Platform 13 (Queens).<br>Red Hat Product Security has rated this update as having a security impact  
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which  
gives a detailed severity rating, is available for each vulnerability from  
the CVE link(s) in the References section. | 2020-12-19 | [https://access.redhat.com/errata/RHSA-2020:5571](https://access.redhat.com/errata/RHSA-2020:5571) |