jQuery — набор функций JavaScript, фокусирующийся на взаимодействии JavaScript и HTML.
Релизный цикл, информация об уязвимостях
График релизов
Количество 85
GHSA-q44p-q588-242q
jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside after.
GHSA-579v-mp3v-rrw5
jQuery vulnerable to Cross-Site Scripting (XSS)
GHSA-w97x-8w5v-6mh4
The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."
ELSA-2021-9400
ELSA-2021-9400: bootstrap security update (IMPORTANT)
ELSA-2021-1846
ELSA-2021-1846: idm:DL1 and idm:client security, bug fix, and enhancement update (MODERATE)
ELSA-2021-1846-1
ELSA-2021-1846-1: idm:client security, bug fix, and enhancement update (MODERATE)
RLSA-2021:1846
Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update
ELSA-2021-0860
ELSA-2021-0860: ipa security and bug fix update (MODERATE)
GHSA-2pqj-h3vj-pqgw
Cross-Site Scripting in jquery
BDU:2023-07536
Уязвимость библиотеки jQuery, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить межсайтовую сценарную атаку
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-q44p-q588-242q jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside after. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-579v-mp3v-rrw5 jQuery vulnerable to Cross-Site Scripting (XSS) | 19% Средний | больше 4 лет назад | ||
GHSA-w97x-8w5v-6mh4 The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking." | 3% Низкий | больше 4 лет назад | ||
ELSA-2021-9400 ELSA-2021-9400: bootstrap security update (IMPORTANT) | 84% Высокий | около 5 лет назад | ||
ELSA-2021-1846 ELSA-2021-1846: idm:DL1 and idm:client security, bug fix, and enhancement update (MODERATE) | 84% Высокий | больше 5 лет назад | ||
ELSA-2021-1846-1 ELSA-2021-1846-1: idm:client security, bug fix, and enhancement update (MODERATE) | 84% Высокий | больше 5 лет назад | ||
RLSA-2021:1846 Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update | 84% Высокий | больше 5 лет назад | ||
ELSA-2021-0860 ELSA-2021-0860: ipa security and bug fix update (MODERATE) | 84% Высокий | больше 5 лет назад | ||
GHSA-2pqj-h3vj-pqgw Cross-Site Scripting in jquery | CVSS3: 6.1 | 9% Низкий | около 6 лет назад | |
BDU:2023-07536 Уязвимость библиотеки jQuery, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить межсайтовую сценарную атаку | CVSS3: 6.1 | 6% Низкий | больше 6 лет назад |
Уязвимостей на страницу