QID 981486
QID 981486: Nodejs (npm) Security Update for jquery (GHSA-q4m3-2j7h-f7xw)
Versions of `jquery` prior to 1.9.0 are vulnerable to Cross-Site Scripting. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed. This allows attackers to execute arbitrary JavaScript in a victim's browser.
## Recommendation
Upgrade to version 1.9.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q4m3-2j7h-f7xw for updates pertaining to this vulnerability.
Vendor References
- GHSA-q4m3-2j7h-f7xw -
github.com/advisories/GHSA-q4m3-2j7h-f7xw
CVEs related to QID 981486
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q4m3-2j7h-f7xw | jquery |
|