---
title: "CVE-2019-8331"
canonical: "https://kb.cynergy.app/space/MD/899351014/CVE-2019-8331"
format: markdown
---
**Description:**

In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.

**Published On:**

2019-02-11

**Updated On:**

2/11/2019

**Trending:**

FALSE

**CWE:**

CWE-79

**Mitigation:**

![image](media://b859c002-451f-4cbf-88a8-7bbf2ffc3a84)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |
| --- | --- | --- | --- | --- |
| Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| OpenSource | ipa-4.6.8-5.el7 | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:3936](https://access.redhat.com/errata/RHSA-2020:3936) |
| apache | jss-4.7.3-1.module+el8.3.0+8058+d5cd4219 | An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:4847](https://access.redhat.com/errata/RHSA-2020:4847) |
| OpenSource | bind-dyndb-ldap-11.3-1.module+el8.3.0+6993+104f8db0 | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:4670](https://access.redhat.com/errata/RHSA-2020:4670) |
| redhat | Red Hat Security Advisory: Red Hat Single Sign-On 7.3.2 security update | A security update is now available for Red Hat Single Sign-On 7.3 from the Customer Portal.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-06-12 | [https://access.redhat.com/errata/RHSA-2019:1456](https://access.redhat.com/errata/RHSA-2019:1456) |
| redhat | Red Hat Security Advisory: ovirt-engine-ui-extensions security and bug fix update | An update for ovirt-engine-ui-extensions is now available for Red Hat Virtualization Engine 4.3.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-11 | [https://access.redhat.com/errata/RHSA-2019:3023](https://access.redhat.com/errata/RHSA-2019:3023) |
| redhat | Red Hat Security Advisory: ovirt-web-ui security and bug fix update | An update for ovirt-web-ui is now available for Red Hat Virtualization Engine 4.3.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-11 | [https://access.redhat.com/errata/RHSA-2019:3024](https://access.redhat.com/errata/RHSA-2019:3024) |
| redhat | Red Hat Security Advisory: RHV Manager (ovirt-engine) 4.4 security, bug fix, and enhancement update | Updated ovirt-engine packages that fix several bugs and add various enhancements are now available.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-08-05 | [https://access.redhat.com/errata/RHSA-2020:3247](https://access.redhat.com/errata/RHSA-2020:3247) |
| redhat | Red Hat Security Advisory: ipa security, bug fix, and enhancement update | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-10 | [https://access.redhat.com/errata/RHSA-2020:3936](https://access.redhat.com/errata/RHSA-2020:3936) |
| redhat | Red Hat Security Advisory: idm:DL1 and idm:client security, bug fix, and enhancement update | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-11-05 | [https://access.redhat.com/errata/RHSA-2020:4670](https://access.redhat.com/errata/RHSA-2020:4670) |
| redhat | Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update | An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-11-05 | [https://access.redhat.com/errata/RHSA-2020:4847](https://access.redhat.com/errata/RHSA-2020:4847) |
| redhat | Red Hat Security Advisory: python-XStatic-Bootstrap-SCSS security update | An update for python-XStatic-Bootstrap-SCSS is now available for Red Hat  
OpenStack Platform 13 (Queens).<br>Red Hat Product Security has rated this update as having a security impact  
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which  
gives a detailed severity rating, is available for each vulnerability from  
the CVE link(s) in the References section. | 2020-12-19 | [https://access.redhat.com/errata/RHSA-2020:5571](https://access.redhat.com/errata/RHSA-2020:5571) |
| oracle | Oracle Critical Patch Update Advisory - April 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-05-06 | [https://www.oracle.com/security-alerts/cpuapr2021.html](https://www.oracle.com/security-alerts/cpuapr2021.html) |