Reflected cross-site scripting (XSS) In org.webjars:jquery
Description
Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rubygems | 4.4.0 | ||
packagist | 1.19.0 | ||
packagist | 3.5.0 | ||
packagist | 8.0.0, 8.7.14, 8.8.6 | ||
debian 14 | 3.5.0+dfsg-2 | ||
maven | 3.5.0 | ||
nuget | 3.5.0 | ||
rpm rhel7 | - | - | |
rpm rhel6 | - | - | |
packagist | 4.0.1 |
1-10 of 29
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33. 34. 35. 36. 37. 38. 39. 40. 41. 42. 43. 44. 45.