HIGH7.5
GHSA-mhpp-875w-9cpv
Denial of Service in jquery
Quick fix
GHSA-mhpp-875w-9cpv — jquery: upgrade to the fixed version with the command below.
npm install jquery@3.0.0Details
Affected versions of `jquery` use a lowercasing logic on attribute names. When given a boolean attribute with a name that contains uppercase characters, `jquery` enters into an infinite recursion loop, exceeding the call stack limit, and resulting in a denial of service condition.
## Recommendation
Update to version 3.0.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.webjars.npm:jquery
Introduced in:
3.0.0-rc1Fixed in: 3.0.0Fix
# pom.xml: bump <version>3.0.0</version> for org.webjars.npm:jqueryReferences
- https://nvd.nist.gov/vuln/detail/CVE-2016-10707[ADVISORY]
- https://github.com/jquery/jquery/issues/3133[WEB]
- https://github.com/jquery/jquery/issues/3133#issuecomment-358978489[WEB]
- https://github.com/jquery/jquery/pull/3134[WEB]
- https://github.com/advisories/GHSA-mhpp-875w-9cpv[ADVISORY]
- https://github.com/jquery/jquery[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2016-10707.yml[WEB]
- https://snyk.io/vuln/npm:jquery:20160529[WEB]
- https://www.npmjs.com/advisories/330[WEB]