Описание
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "", which results in the enclosed script logic to be executed.
A flaw was found in jquery in versions prior to 1.9.0. A cross-site scripting attack is possible as the load method fails to recognize and remove "
Отчет
Red Hat Enterprise Linux version 6, 7 and 8 ship a vulnerable version of JQuery in the pcs
component. However the vulnerable has not been found to be exploitable in reasonable scenarios. A future update may update JQuery to a fixed version.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
CloudForms Management Engine 5 | jquery-rails | Not affected | ||
OpenShift Service Mesh 1 | kiali | Not affected | ||
OpenShift Service Mesh 1 | servicemesh-grafana | Not affected | ||
OpenShift Service Mesh 1 | servicemesh-prometheus | Not affected | ||
Red Hat 3scale API Management Platform 2 | jquery | Will not fix | ||
Red Hat Ceph Storage 3 | grafana | Not affected | ||
Red Hat Ceph Storage 3 | grafana-container | Not affected | ||
Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Not affected | ||
Red Hat Enterprise Linux 6 | ipa | Not affected | ||
Red Hat Enterprise Linux 6 | pcp | Out of support scope |
Показывать по
Дополнительная информация
Статус:
5.4 Medium
CVSS3
Связанные уязвимости
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load ...
Уязвимость библиотеки jQuery, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить межсайтовую сценарную атаку
5.4 Medium
CVSS3