Reflected cross-site scripting (XSS) In jquery-rails
Description
Affected versions of this package are vulnerable to Cross-site Scripting (XSS). load() fails to recognize and remove script HTML tags that contain a whitespace character, i.e: which results in the enclosed script logic to be executed. This can lead to Cross-site Scripting attacks when an attacker has control of the enclosed script.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 2.2.0 | ||
maven | 1.9.0 | ||
nuget | 1.9.0, 1.9.0 | ||
npm | 1.9.0 | ||
rubygems | 2.0.0 | ||
maven | - | ||
rpm rhel6 | - | - | |
rpm rhel6 | - | - | |
rpm rhel7 | - | - | |
rpm rhel7 | - | - |
1-10 of 16
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.