GHSA-rmxg-73gg-4p98

Suggest an improvement
Source
https://github.com/advisories/GHSA-rmxg-73gg-4p98
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-rmxg-73gg-4p98/GHSA-rmxg-73gg-4p98.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rmxg-73gg-4p98
Aliases
Published
2018-01-22T13:32:06Z
Modified
2024-03-10T05:18:22.438189Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Cross-Site Scripting (XSS) in jquery
Details

Affected versions of jquery interpret text/javascript responses from cross-origin ajax requests, and automatically execute the contents in jQuery.globalEval, even when the ajax request doesn't contain the dataType option.

Recommendation

Update to version 3.0.0 or later.

References

Affected packages

npm / jquery

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.2

NuGet / jQuery

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.2

Affected versions

1.*

1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.1.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.10.0
1.10.0.1
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1

NuGet / jQuery

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.12.3
Fixed
3.0.0

Affected versions

1.*

1.12.3
1.12.4

2.*

2.0.0
2.0.1
2.0.1.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4

npm / jquery

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.12.3
Fixed
3.0.0

RubyGems / jquery-rails

Package

Name
jquery-rails
Purl
pkg:gem/jquery-rails

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.0

Affected versions

0.*

0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7

1.*

1.0.rc
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19

2.*

2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5

4.*

4.0.0.beta1
4.0.0.beta2
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1

Maven / org.webjars.npm:jquery

Package

Name
org.webjars.npm:jquery
View open source insights on deps.dev
Purl
pkg:maven/org.webjars.npm/jquery

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.2

Affected versions

1.*

1.7.2
1.7.3
1.8.2
1.8.3
1.9.1
1.11.0
1.11.1
1.11.3
1.12.1

Maven / org.webjars.npm:jquery

Package

Name
org.webjars.npm:jquery
View open source insights on deps.dev
Purl
pkg:maven/org.webjars.npm/jquery

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.12.3
Fixed
3.0.0

Affected versions

1.*

1.12.3
1.12.4

2.*

2.1.0
2.1.1-rc1
2.1.1-rc2
2.1.1
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4

3.*

3.0.0-alpha1
3.0.0-beta1
3.0.0-rc1