You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
Mend Note: Converted from WS-2018-0021, on 2022-11-08.
dev-mend-for-github-combot
changed the title
phalcon/devtools-v3.2.9: 10 vulnerabilities (highest severity is: 7.5)
phalcon/devtools-v3.2.9: 10 vulnerabilities (highest severity is: 6.9)
Jul 4, 2024
dev-mend-for-github-combot
changed the title
phalcon/devtools-v3.2.9: 10 vulnerabilities (highest severity is: 6.9)
phalcon/devtools-v3.2.9: 1 vulnerabilities (highest severity is: 3.7)
Jul 11, 2024
dev-mend-for-github-combot
changed the title
phalcon/devtools-v3.2.9: 1 vulnerabilities (highest severity is: 3.7)
phalcon/devtools-v3.2.9: 2 vulnerabilities (highest severity is: 5.3)
Jul 12, 2024
dev-mend-for-github-combot
changed the title
phalcon/devtools-v3.2.9: 2 vulnerabilities (highest severity is: 5.3)
phalcon/devtools-v3.2.9: 3 vulnerabilities (highest severity is: 5.3)
Jul 24, 2024
dev-mend-for-github-combot
changed the title
phalcon/devtools-v3.2.9: 3 vulnerabilities (highest severity is: 5.3)
phalcon/devtools-v3.2.9: 4 vulnerabilities (highest severity is: 6.1)
Aug 10, 2024
dev-mend-for-github-combot
changed the title
phalcon/devtools-v3.2.9: 4 vulnerabilities (highest severity is: 6.1)
phalcon/devtools-v3.2.9: 4 vulnerabilities (highest severity is: 9.8)
Nov 25, 2024
dev-mend-for-github-combot
changed the title
phalcon/devtools-v3.2.9: 4 vulnerabilities (highest severity is: 9.8)
phalcon/devtools-v3.2.9: 4 vulnerabilities (highest severity is: 6.1)
Nov 25, 2024
Vulnerable Library - phalcon/devtools-v3.2.9
This tools provide you useful scripts to generate code helping to develop faster and easy applications that use with Phalcon framework.
Library home page: https://api.github.com/repos/phalcon/phalcon-devtools/zipball/61ece695c233f4bf16be1488dfc61649fc8ba1c3
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2019-8331
Vulnerable Library - phalcon/devtools-v3.2.9
This tools provide you useful scripts to generate code helping to develop faster and easy applications that use with Phalcon framework.
Library home page: https://api.github.com/repos/phalcon/phalcon-devtools/zipball/61ece695c233f4bf16be1488dfc61649fc8ba1c3
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Publish Date: 2019-02-20
URL: CVE-2019-8331
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2019-02-20
Fix Resolution: bootstrap - 3.4.1,4.3.1;bootstrap-sass - 3.4.1,4.3.1
CVE-2020-7760
Vulnerable Library - phalcon/devtools-v3.2.9
This tools provide you useful scripts to generate code helping to develop faster and easy applications that use with Phalcon framework.
Library home page: https://api.github.com/repos/phalcon/phalcon-devtools/zipball/61ece695c233f4bf16be1488dfc61649fc8ba1c3
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/.?/)
Publish Date: 2020-10-30
URL: CVE-2020-7760
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7760
Release Date: 2020-10-30
Fix Resolution: codemirror - 5.58.2
CVE-2018-20676
Vulnerable Library - phalcon/devtools-v3.2.9
This tools provide you useful scripts to generate code helping to develop faster and easy applications that use with Phalcon framework.
Library home page: https://api.github.com/repos/phalcon/phalcon-devtools/zipball/61ece695c233f4bf16be1488dfc61649fc8ba1c3
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
Publish Date: 2019-01-09
URL: CVE-2018-20676
CVSS 3 Score Details (3.7)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20676
Release Date: 2019-01-09
Fix Resolution: bootstrap - 3.4.0
CVE-2016-10735
Vulnerable Library - phalcon/devtools-v3.2.9
This tools provide you useful scripts to generate code helping to develop faster and easy applications that use with Phalcon framework.
Library home page: https://api.github.com/repos/phalcon/phalcon-devtools/zipball/61ece695c233f4bf16be1488dfc61649fc8ba1c3
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
Mend Note: Converted from WS-2018-0021, on 2022-11-08.
Publish Date: 2019-01-09
URL: CVE-2016-10735
CVSS 3 Score Details (3.7)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2019-01-09
Fix Resolution: 3.4.0
The text was updated successfully, but these errors were encountered: