Reflected cross-site scripting (XSS) In jquery-ui-rails
Description
jquery-ui Tooltip widget vulnerable to XSS Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 4.0.0 | ||
debian 12 | 1.10.1+dfsg-1 | ||
maven | 1.10.0 | ||
nuget | 1.10.0 | ||
debian 13 | 1.10.1+dfsg-1 | ||
debian 14 | 1.10.1+dfsg-1 | ||
npm | 1.10.0 | ||
debian 11 | 1.10.1+dfsg-1 | ||
rpm rhel7 | 0:4.1.0-18.el7 | ||
rpm rhel6 | 0:3.0.0-47.el6 |
1-10 of 13
10
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.