QID 980695
QID 980695: Nodejs (npm) Security Update for jqtree (GHSA-gjhx-gxwx-jx9j)
Affected versions of `jqtree` are vulnerable to cross-site scripting in the drag and drop functionality for modifying tree data.
When a user attempts to drag a node to a different position in the hierarchy, script content existing within the node will be executed.
## Recommendation
Update to 1.3.4 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gjhx-gxwx-jx9j for updates pertaining to this vulnerability.
Vendor References
- GHSA-gjhx-gxwx-jx9j -
github.com/advisories/GHSA-gjhx-gxwx-jx9j
CVEs related to QID 980695
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gjhx-gxwx-jx9j | jqtree |
|