VDB
Sign up
MEDIUM6.1

GHSA-q4m3-2j7h-f7xw

Cross-Site Scripting in jquery

Quick fix

GHSA-q4m3-2j7h-f7xw — jquery: upgrade to the fixed version with the command below.

npm install jquery@1.9.0

Details

Versions of `jquery` prior to 1.9.0 are vulnerable to Cross-Site Scripting. The load method fails to recognize and remove `<script>` HTML tags that contain a whitespace character, i.e: `</script >`, which results in the enclosed script logic to be executed. This allows attackers to execute arbitrary JavaScript in a victim's browser.

## Recommendation

Upgrade to version 1.9.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jquery
Introduced in: 1.2.1Fixed in: 1.9.0
Fixnpm install jquery@1.9.0
NuGet/jQuery
Introduced in: 1.2.1Fixed in: 1.9.0
Fixdotnet add package jQuery --version 1.9.0
RubyGems/jquery-rails
Introduced in: 0Fixed in: 2.2.0
Fixbundle update jquery-rails
Maven/org.webjars.npm:jquery
Introduced in: 1.2.1Fixed in: 1.9.0
Fix# pom.xml: bump <version>1.9.0</version> for org.webjars.npm:jquery

References