In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.
{ "binaries": [ { "binary_version": "3.3.6+dfsg-1ubuntu0.1~esm1", "binary_name": "libjs-bootstrap" } ] }
{ "binaries": [ { "binary_version": "3.3.7+dfsg-2ubuntu0.1~esm1", "binary_name": "libjs-bootstrap" } ] }