logo

Database

Reflected cross-site scripting (XSS) In org.webjars:jquery

Description

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

1-10 of 28

10

References

1. https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px22. https://github.com/maximebf/php-debugbar/issues/4473. https://github.com/jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f774. https://github.com/maximebf/php-debugbar/commit/847216e60544258c881f2733d699bbcfeefac0fc5. https://blog.jquery.com/2020/04/10/jquery-3-5-0-released6. https://lists.fedoraproject.org/archives/list/[email protected]/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W7. https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html8. https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html9. https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html10. https://packetstormsecurity.com/files/162159/jQuery-1.2-Cross-Site-Scripting.html11. https://www.debian.org/security/2020/dsa-469312. https://www.drupal.org/sa-core-2020-00213. https://www.oracle.com//security-alerts/cpujul2021.html14. https://www.oracle.com/security-alerts/cpuApr2021.html15. https://www.oracle.com/security-alerts/cpuapr2022.html16. https://www.oracle.com/security-alerts/cpujan2021.html17. https://www.oracle.com/security-alerts/cpujan2022.html18. https://www.oracle.com/security-alerts/cpujul2020.html19. https://www.oracle.com/security-alerts/cpujul2022.html20. https://www.oracle.com/security-alerts/cpuoct2020.html21. https://www.oracle.com/security-alerts/cpuoct2021.html22. https://github.com/Athlon1600/youtube-downloader/releases/tag/v4.0.123. https://github.com/jquery/jquery/releases/tag/3.5.024. https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2020-11022.yml25. https://jquery.com/upgrade-guide/3.526. https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36@%3Cissues.flink.apache.org%3E27. https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48@%3Cissues.flink.apache.org%3E28. https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae@%3Cissues.flink.apache.org%3E29. https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760@%3Cissues.flink.apache.org%3E30. https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d@%3Cissues.flink.apache.org%3E31. https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c@%3Cissues.flink.apache.org%3E32. https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67@%3Cdev.flink.apache.org%3E33. https://lists.apache.org/thread.html/rdf44341677cf7eec7e9aa96dcf3f37ed709544863d619cca8c36f133@%3Ccommits.airflow.apache.org%3E34. https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108@%3Cissues.flink.apache.org%3E35. https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4@%3Cissues.flink.apache.org%3E36. https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2@%3Cissues.flink.apache.org%3E37. https://lists.fedoraproject.org/archives/list/[email protected]/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY38. https://lists.fedoraproject.org/archives/list/[email protected]/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K39. https://lists.fedoraproject.org/archives/list/[email protected]/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD440. https://lists.fedoraproject.org/archives/list/[email protected]/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B41. http://security.netapp.com/advisory/ntap-20200511-000642. https://vulncheck.com/cve/CVE-2020-1102243. https://github.com/0xAJ2K/CVE-2020-11022-CVE-2020-1102344. https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/45. https://jquery.com/upgrade-guide/3.5/
FLAT-2VW72 – Vulnerability | Fluid Attacks Database