Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-9251

Опубликовано: 27 июн. 2015
Источник: redhat
CVSS3: 6.1
CVSS2: 4.3
EPSS Средний

Описание

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 2jqueryFix deferred
Red Hat Enterprise Linux 7pcsNot affected
Red Hat Enterprise Linux 7pki-coreWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-XStatic-jQueryWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installerruby193-rubygem-jquery-ui-railsWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-XStatic-jQueryWill not fix
Red Hat OpenShift Enterprise 2ruby193-rubygem-jquery-railsWill not fix
Red Hat OpenStack Platform 10 (Newton)python-XStatic-jQueryWill not fix
Red Hat OpenStack Platform 11 (Ocata)python-XStatic-jQueryWill not fix
Red Hat OpenStack Platform 8 (Liberty)python-XStatic-jQueryWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1399546jquery: Cross-site scripting via cross-domain ajax requests

EPSS

Процентиль: 93%
0.11287
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 7 лет назад

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

CVSS3: 6.1
nvd
больше 7 лет назад

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

CVSS3: 6.1
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 6.1
debian
больше 7 лет назад

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attack ...

CVSS3: 6.1
github
больше 7 лет назад

Cross-Site Scripting (XSS) in jquery

EPSS

Процентиль: 93%
0.11287
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2