Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-8331

27
FAUCET Score

CVE-2019-8331 describes a Cross-Site Scripting (XSS) vulnerability in Bootstrap versions prior to 3.4.1 and 4.3.1, specifically within the tooltip or popover data-template attribute, affecting products like F5, Red Hat, and Tenable. Rated Medium (CVSS 6.1), it requires user interaction (UI:R) and can lead to low impact on confidentiality and integrity, with a network attack vector and low attack complexity. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, though it has garnered some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.4.1CPE matchmatch criteria
cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:*
>= 4.3.0, < 4.3.1CPE matchmatch criteria
cpe:2.3:a:getbootstrap:bootstrap:*:*:*:*:*:*:*:*
>= 12.1.0, < 12.1.5.1CPE matchmatch criteria
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
>= 13.0.0, < 13.1.3.4CPE matchmatch criteria
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
>= 14.0.0, < 14.1.2.5CPE matchmatch criteria
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
16.86%
Probability of exploitation in next 30 days
EPSS Percentile
96.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.1686 is in the 99th percentile among its peer group of 26,209 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (44)

composerpatch availablevia ghsa
Product: twbs/bootstrapFixed in: 3.4.1
composerpatch availablevia ghsa
Product: twbs/bootstrapFixed in: 4.3.1
github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.webjars:bootstrapFixed in: 4.3.1
mavenpatch availablevia ghsa
Product: org.webjars:bootstrapFixed in: 3.4.1
npmpatch availablevia ghsa
Product: bootstrapFixed in: 3.4.1
npmpatch availablevia ghsa
Product: bootstrapFixed in: 4.3.1
npmpatch availablevia ghsa
Product: bootstrap-sassFixed in: 3.4.1
nugetpatch availablevia ghsa
Product: bootstrapFixed in: 3.4.1
nugetpatch availablevia ghsa
Product: bootstrapFixed in: 4.3.1
nugetpatch availablevia ghsa
Product: bootstrap.sassFixed in: 4.3.1
nugetpatch availablevia ghsa
Product: Bootstrap.LessFixed in: 3.4.1
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSFixed in: python-XStatic-Bootstrap-SCSS-0:3.4.1.0-1.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: bootstrap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 13.0 (Queens)Fixed in: python-XStatic-Bootstrap-SCSS-0:3.4.1.0-1.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.1Fixed in: python-XStatic-Bootstrap-SCSS-0:3.4.1.0-2.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: python-XStatic-Bootstrap-SCSS-0:3.4.1.0-2.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.3.2 zipFixed in: bootstrap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.3Fixed in: ovirt-engine-ui-extensions-0:1.0.10-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.3Fixed in: ovirt-web-ui-0:1.6.0-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: org.ovirt.engine-root-0:4.4.1.8-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: ovirt-engine-api-explorer-0:0.0.6-1.el8ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ipa-0:4.6.8-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: idm:client-8030020200923172426.05ac3f11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: idm:DL1-8030020200923172343.9c827e52
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-core:10.6-8030020200911215836.5ff1562f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-deps:10.6-8030020200527165326.30b713e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.11.1Fixed in: io.hawt-hawtio-online
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.11.1Fixed in: io.hawt-project
View patch
rubygemspatch availablevia ghsa
Product: bootstrapFixed in: 4.3.1
rubygemspatch availablevia ghsa
Product: twitter-bootstrap-railsFixed in: 5.3.0
rubygemspatch availablevia ghsa
Product: bootstrap-sassFixed in: 3.4.1
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 14 (Rocky)Fixed in: python-XStatic-Bootstrap-SCSS
redhatno patchvia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: bootstrap
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 8 (Liberty)Fixed in: python-XStatic-Bootstrap-SCSS
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka)Fixed in: python-XStatic-Bootstrap-SCSS
redhatend of lifevia redhat_api
Product: Red Hat Process Automation 7Fixed in: bootstrap
redhatend of lifevia redhat_api
Product: Red Hat Decision Manager 7Fixed in: bootstrap
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: pki-core
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: python-XStatic-Bootstrap-SCSS
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 15 (Stein)Fixed in: python-XStatic-Bootstrap-SCSS

Vendor Advisories (2)

rubygemsGHSA-9v3m-8fp8-mj99medium

Bootstrap Vulnerable to Cross-Site Scripting

Feb 22, 2019
redhatCVE-2019-8331Moderate

bootstrap: XSS in the tooltip or popover data-template attribute

Feb 11, 2019

References

packetstormsecurity.com / files/156743/OctoberCMS-Insecure-Dependencies.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2019:1456
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3023
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3024
Third Party Advisory
blog.getbootstrap.com / 2019/02/13/bootstrap-4-3-1-and-3-4-1
Vendor Advisory
seclists.org / fulldisclosure/2019/May/10
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2019/May/11
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2019/May/13
Mailing ListThird Party Advisory
github.com / twbs/bootstrap/pull/28236
Issue TrackingPatchThird Party Advisory
github.com / twbs/bootstrap/releases/tag/v3.4.1
ProductThird Party Advisory
github.com / twbs/bootstrap/releases/tag/v4.3.1
Release NotesThird Party Advisory
lists.apache.org / thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%3E
lists.apache.org / thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org%3E
lists.apache.org / thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org%3E
lists.apache.org / thread.html/52e0e6b5df827ee7f1e68f7cc3babe61af3b2160f5d74a85469b7b0e%40%3Cdev.superset.apache.org%3E
lists.apache.org / thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org%3E
lists.apache.org / thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
lists.apache.org / thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
lists.apache.org / thread.html/r3dc0cac8d856bca02bd6997355d7ff83027dcfc82f8646a29b89b714%40%3Cissues.hbase.apache.org%3E
lists.apache.org / thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E
seclists.org / bugtraq/2019/May/18
Mailing ListThird Party Advisory
support.f5.com / csp/article/K24383845
Third Party Advisory
support.f5.com / csp/article/K24383845
oracle.com / security-alerts/cpuApr2021.html
Third Party Advisory
tenable.com / security/tns-2021-14
PatchThird Party Advisory
securityfocus.com / bid/107375
Third Party AdvisoryVDB Entry