Описание
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-apps/xenial | needs-triage | |
esm-infra-legacy/trusty | needs-triage | |
esm-infra/focal | DNE | |
focal | DNE | |
groovy | DNE | |
hirsute | DNE | |
impish | DNE | |
jammy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needs-triage |
devel | DNE | |
eoan | ignored | end of life |
esm-infra-legacy/trusty | not-affected | code not present |
esm-infra/bionic | needs-triage | |
esm-infra/focal | not-affected | 3.3.1~dfsg-3ubuntu0.1 |
esm-infra/xenial | needs-triage | |
focal | released | 3.3.1~dfsg-3ubuntu0.1 |
groovy | DNE | |
hirsute | DNE |
Показывать по
EPSS
4.3 Medium
CVSS2
6.9 Medium
CVSS3
Связанные уязвимости
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
In jQuery versions greater than or equal to 1.2 and before 3.5.0, pass ...
Уязвимость библиотеки jQuery, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
EPSS
4.3 Medium
CVSS2
6.9 Medium
CVSS3