VDB
Sign up
MEDIUM

GHSA-579v-mp3v-rrw5

jQuery vulnerable to Cross-Site Scripting (XSS)

Quick fix

GHSA-579v-mp3v-rrw5 — jquery: upgrade to the fixed version with the command below.

npm install jquery@1.6.3

Details

Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jquery
Introduced in: 0Fixed in: 1.6.3
Fixnpm install jquery@1.6.3
NuGet/jQuery
Introduced in: 0Fixed in: 1.6.3
Fixdotnet add package jQuery --version 1.6.3
RubyGems/jquery-rails
Introduced in: 0Fixed in: 1.0.16
Fixbundle update jquery-rails
Maven/org.webjars.npm:jquery
Introduced in: 0Fixed in: 1.6.3
Fix# pom.xml: bump <version>1.6.3</version> for org.webjars.npm:jquery

References