# Bootstrap vulnerabilities

**URL:** <https://discuss.elastic.co/t/bootstrap-vulnerabilities/300124>\
**Category:** Kibana\
**Created:** [March 20, 2022, 11:52am UTC](https://discuss.elastic.co/t/bootstrap-vulnerabilities/300124 "2022-03-20T11:52:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![frenkel](https://avatars.discourse-cdn.com/v4/letter/f/dec6dc/32.png) [@frenkel](https://discuss.elastic.co/u/frenkel)\
**Post date:** [March 20, 2022, 11:52am UTC](https://discuss.elastic.co/t/bootstrap-vulnerabilities/300124/1 "2022-03-20T11:52:36Z")

</div>

Hi

I have a question about bootstrap vulnerabilities.

In bootstrap versions below 4.1.2, these 3 vulnerabilities have been found:

> **[CVE -
CVE-2018-14040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14040)**
>
> The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

> **[CVE -
CVE-2018-14041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14041)**
>
> The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

> **[CVE -
CVE-2018-14042](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14042)**
>
> The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

We are using Kibana as part of our solution and when digging into the files we saw that Kibana contains references to bootstrap version 3.1.1. (e.g. link rel="stylesheet" href="[https://netdna.bootstrapcdn.com/bootstrap/3.1.1/css/bootstrap.css](https://netdna.bootstrapcdn.com/bootstrap/3.1.1/css/bootstrap.css)").

However when checking the source files in the browser (when running the project) we can't find bootstrap.css or bootstrap.min.css.

I saw on an older thread that you are migrating the bootstrap code to one of your own:

> [@What version of bootstrap is Kibana using?](https://discuss.elastic.co/t/what-version-of-bootstrap-is-kibana-using/168476):
>
> Hello there! We are using the ELK stack at work for a bigger project and recently we come across creating some custom plugins. However, I'm not sure what version of bootstrap is embedded into Kibana. I'm trying to use some components and styles and sometimes they work, sometime not. Among the installed modules for the plugin, I have "angular-ui-bootstrap": "2.5.6" . Right now I am using the 6.2.3 release, but I can switch if needed (preferably I'd like to use Bootstrap v4). Thanks!

My question is - is Kibana affected by those 3 vulnerabilities? We are a bit confused as to whether or not Kibana uses the relevant code of bootstrap.

Thanks

---

<div class="post-metadata">

**Author:** ![Marta\_Bondyra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_bondyra/32/102122_2.png) [@Marta\_Bondyra](https://discuss.elastic.co/u/Marta_Bondyra)\
**Post date:** [March 21, 2022, 12:54pm UTC](https://discuss.elastic.co/t/bootstrap-vulnerabilities/300124/2 "2022-03-21T12:54:33Z")

</div>

Hello, what version of Kibana are you checking? I've looked at the newest release and couldn't find any reference to bootstrap.

---

<div class="post-metadata">

**Author:** ![frenkel](https://avatars.discourse-cdn.com/v4/letter/f/dec6dc/32.png) [@frenkel](https://discuss.elastic.co/u/frenkel)\
**Post date:** [March 22, 2022, 7:32am UTC](https://discuss.elastic.co/t/bootstrap-vulnerabilities/300124/3 "2022-03-22T07:32:34Z")

</div>

Hi Marta,  
We are using Kibana 7.8.0.

---

<div class="post-metadata">

**Author:** ![frenkel](https://avatars.discourse-cdn.com/v4/letter/f/dec6dc/32.png) [@frenkel](https://discuss.elastic.co/u/frenkel)\
**Post date:** [March 22, 2022, 9:04am UTC](https://discuss.elastic.co/t/bootstrap-vulnerabilities/300124/4 "2022-03-22T09:04:44Z")

</div>

It looks like all the bootstrap.css references are in this directory:  
node\_modules/ui-select/

one example is:  
node\_modules/ui-select/docs-out/demo-bootstrap.html

---

<div class="post-metadata">

**Author:** ![frenkel](https://avatars.discourse-cdn.com/v4/letter/f/dec6dc/32.png) [@frenkel](https://discuss.elastic.co/u/frenkel)\
**Post date:** [March 28, 2022, 6:51am UTC](https://discuss.elastic.co/t/bootstrap-vulnerabilities/300124/5 "2022-03-28T06:51:18Z")

</div>

Hi,  
Is there any update on the issue?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2022, 6:52am UTC](https://discuss.elastic.co/t/bootstrap-vulnerabilities/300124/6 "2022-04-25T06:52:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
