← 戻る
CVE-2018-14041
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
AI要約 snake-internal / snake-template-v1
In Bootstrap beforeという製品で、CVE-2018-14041 という番号がついた弱点 (脆弱性) が見つかりました。
重要度は「情報」。深刻度は低いか、まだ評価されていません。
あなた自身の対応としては、使っている製品やソフトを最新版に更新するのがいちばんの対策です。心配なら、システム担当者や製品の公式サイトで「In Bootstrap before CVE-2018-14041」を検索してください。
CVE-2018-14041 (In Bootstrap before)。重要度: 情報。
対応方針:
1. ベンダー公式アドバイザリで影響バージョン・修正版を確認
2. 該当バージョンが本番で稼働中なら、メンテ計画 (緊急度はKEV/CVSSで判断)
3. パッチ未提供時は WAF ルール・該当機能の無効化等で暫定回避
4. ログ・SIEMで該当CVEのIOC/PoCシグネチャを監視
詳細PoCや修正コミットは、当ページの『参照URL』および MITRE / NVD を参照してください。
❓ 何が問題か
In Bootstrap before の弱点 (CVE-2018-14041)。深刻なソフトウェア欠陥が見つかっています。
📍 影響範囲
In Bootstrap before の対象バージョン (各ベンダーアドバイザリで確認)。本番環境で稼働中であれば直ちに影響範囲を確認してください。
🔥 重要度
重要度: 情報。深刻度は低いか、まだ評価されていません。
🔧 修正方法
ベンダー公式アドバイザリで提示された修正版に更新してください。
🛡️ 暫定回避
修正版がまだ提供されていない場合は、影響機能の無効化・WAFルール・ネットワークACLでの遮断・該当バージョンの隔離を検討してください。
🔍 検知方法
バージョン情報の確認、SBOMでの依存関係スキャン、SIEMでの該当CVEに関するIOC・PoCシグネチャ監視を実施してください。
参照URL
- advisory https://access.redhat.com/errata/RHSA-2019:1456
- advisory https://blog.getbootstrap.com/2018/07/12/bootstrap-4-1-2/
- patch https://github.com/twbs/bootstrap/pull/26630
- report https://github.com/twbs/bootstrap/issues/26423
- report https://github.com/twbs/bootstrap/issues/26627
- web http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
- web http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
- web http://seclists.org/fulldisclosure/2019/May/10
- web http://seclists.org/fulldisclosure/2019/May/11
- web http://seclists.org/fulldisclosure/2019/May/13
- web https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- web https://lists.apache.org/thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e%40%3Cdev.superset.apache.org%3E
- web https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
- web https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
- web https://lists.apache.org/thread.html/r3dc0cac8d856bca02bd6997355d7ff83027dcfc82f8646a29b89b714%40%3Cissues.hbase.apache.org%3E
- web https://seclists.org/bugtraq/2019/May/18
- web https://www.oracle.com/security-alerts/cpuApr2021.html