Reflected cross-site scripting (XSS) In jquery-rails

Description

cross-site scripting

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions

1-10 of 14

10

References

1. https://github.com/jquery/jquery/commit/05531fc4080ae24070930d15ae0cea7ae056457d2. https://web.archive.org/web/20200227132049/http://www.securityfocus.com/bid/1027923. https://research.insecurelabs.org/jquery/test4. https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E5. https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E6. https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E7. https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.08. https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2012-6708.yml9. https://github.com/rails/jquery-rails/blob/v2.2.0/vendor/assets/javascripts/jquery.js#L6710. https://github.com/rails/jquery-rails/blob/v2.1.4/vendor/assets/javascripts/jquery.js#L5911. https://bugs.jquery.com/ticket/952112. https://bugs.jquery.com/ticket/642913. https://bugs.jquery.com/ticket/1253114. https://bugs.jquery.com/ticket/1129015. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html16. http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html17. http://packetstormsecurity.com/files/161972/Linksys-EA7500-2.0.8.194281-Cross-Site-Scripting.html18. https://www.npmjs.com/advisories/32919. https://nvd.nist.gov/vuln/detail/CVE-2017-1601120. http://www.securityfocus.com/bid/10279221. https://www.ruby-lang.org/en/news/2019/08/28/multiple-jquery-vulnerabilities-in-rdoc/
FLAT-XHNDG – Vulnerability | Fluid Attacks Database