USN-7622-1
Vulnerability Summary
Timeline
Description
jquery vulnerabilities It was discovered that jQuery did not correctly handle HTML tags. An attacker could possibly use this issue to execute a cross-site scripting (XSS) attack. This issue only affected Ubuntu 14.04 LTS. (CVE-2012-6708) It was discovered that jQuery did not correctly handle unsanitized source objects due to prototype pollution. An attacker could possibly use this issue to execute a cross-site scripting (XSS) attack. (CVE-2019-11358) Masato Kinugawa discovered that jQuery did not correctly sanitize certain HTML elements. An attacker could possibly use this issue to execute a cross-site scripting (XSS) attack. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-11022) Masato Kinugawa discovered that jQuery did not correctly sanitize certain HTML elements. An attacker could possibly use this issue to execute a cross-site scripting (XSS) attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-11023)
Affected Systems
- ubuntu•jquery
< 1.7.2+dfsg-2ubuntu1+esm1 | < 1.11.3+dfsg-4ubuntu0.1~esm1 | < 3.2.1-1ubuntu0.1~esm1