{"id":5424720,"name":"jquery","ecosystem":"nuget","description":"jQuery is a new kind of JavaScript Library.\n        jQuery is a fast and concise JavaScript Library that simplifies HTML document traversing, event handling, animating, and Ajax interactions for rapid web development. jQuery is designed to change the way that you write JavaScript.\n        NOTE: This package is maintained on behalf of the library owners by the NuGet Community Packages project at http://nugetpackages.codeplex.com/","homepage":"http://jquery.com/","licenses":null,"normalized_licenses":[],"repository_url":"","keywords_array":["jQuery"],"namespace":null,"versions_count":67,"first_release_published_at":"2011-02-09T07:04:06.707Z","latest_release_published_at":"2023-08-30T17:39:48.267Z","latest_release_number":"3.7.1","last_synced_at":"2026-09-30T00:16:54.155Z","created_at":"2022-11-15T17:47:02.453Z","updated_at":"2026-09-30T12:17:02.817Z","registry_url":"https://www.nuget.org/packages/jquery/","install_command":"Install-Package jquery","documentation_url":null,"metadata":{"owners":"jQuery Foundation, Inc.","license_url":"http://jquery.org/license","require_license_acceptance":false,"language":"en-US","development_dependency":false,"serviceable":false,"framework_assemblies":[],"package_types":[],"verified":false},"repo_metadata":{},"repo_metadata_updated_at":"2026-09-30T00:16:54.440Z","dependent_packages_count":290,"downloads":263640954,"downloads_period":"total","dependent_repos_count":1276,"rankings":{"downloads":0.06547365512795422,"dependent_repos_count":0.08230973787514247,"dependent_packages_count":0.05755925725534438,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":0.06844755008614702},"purl":"pkg:nuget/jquery","advisories":[{"uuid":"GSA_kwCzR0hTQS0yNTdxLXB2ODktdjN4ds4AA0D1","url":"https://github.com/advisories/GHSA-257q-pv89-v3xv","title":"Duplicate Advisory: jQuery Cross Site Scripting vulnerability","description":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of [GHSA-jpcq-cgw6-v4j6](https://github.com/advisories/GHSA-jpcq-cgw6-v4j6). This link is maintained to preserve external references.\n\n## Original Description\n\nCross Site Scripting vulnerability in jQuery v.2.2.0 until v.3.5.0 allows a remote attacker to execute arbitrary code via the `\u003coptions\u003e` element.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-06-26T21:30:58.000Z","withdrawn_at":"2024-05-15T20:10:38.000Z","classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2020-23064","https://snyk.io/vuln/SNYK-JS-JQUERY-565129","https://github.com/jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f77","https://github.com/rails/jquery-rails/blob/master/CHANGELOG.md#410","https://github.com/rails/jquery-rails/blob/master/CHANGELOG.md#440","https://github.com/rails/jquery-rails/blob/v4.3.5/vendor/assets/javascripts/jquery3.js#L5979","https://github.com/rails/jquery-rails/blob/v4.4.0/vendor/assets/javascripts/jquery3.js#L6162","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2020-23064.yml","https://blog.jquery.com/2020/04/10/jquery-3-5-0-released","https://security.netapp.com/advisory/ntap-20230725-0003","https://github.com/advisories/GHSA-jpcq-cgw6-v4j6","https://github.com/advisories/GHSA-257q-pv89-v3xv"],"source_kind":"github","identifiers":["GHSA-257q-pv89-v3xv","CVE-2020-23064"],"repository_url":"https://github.com/jquery/jquery","blast_radius":0.0,"created_at":"2023-07-07T16:03:45.633Z","updated_at":"2026-09-30T11:12:02.127Z","epss_percentage":0.00049,"epss_percentile":0.21662,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNTdxLXB2ODktdjN4ds4AA0D1","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yNTdxLXB2ODktdjN4ds4AA0D1","packages":[{"ecosystem":"rubygems","package_name":"jquery-rails","versions":[{"first_patched_version":"4.4.0","vulnerable_version_range":"\u003c 4.4.0"}],"purl":"pkg:gem/jquery-rails"},{"ecosystem":"nuget","package_name":"jQuery","versions":[{"first_patched_version":"3.5.0","vulnerable_version_range":"\u003e= 1.0.3, \u003c 3.5.0"}],"purl":"pkg:nuget/jQuery"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNTdxLXB2ODktdjN4ds4AA0D1/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01Nzl2LW1wM3YtcnJ3Nc4AATnF","url":"https://github.com/advisories/GHSA-579v-mp3v-rrw5","title":"jQuery vulnerable to Cross-Site Scripting (XSS)","description":"Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-14T01:09:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2011-4969","https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","http://blog.mindedsecurity.com/2011/07/jquery-is-sink.html","http://bugs.jquery.com/ticket/9521","http://www.openwall.com/lists/oss-security/2013/01/31/3","http://www.ubuntu.com/usn/USN-1722-1","https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450224","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2011-4969.yml","https://security.netapp.com/advisory/ntap-20190416-0007","http://blog.jquery.com/2011/09/01/jquery-1-6-3-released","https://github.com/advisories/GHSA-579v-mp3v-rrw5"],"source_kind":"github","identifiers":["GHSA-579v-mp3v-rrw5","CVE-2011-4969"],"repository_url":"https://github.com/jquery/jquery","blast_radius":0.0,"created_at":"2022-12-21T16:11:59.680Z","updated_at":"2026-09-30T11:12:03.325Z","epss_percentage":0.19191,"epss_percentile":0.96977,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Nzl2LW1wM3YtcnJ3Nc4AATnF","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01Nzl2LW1wM3YtcnJ3Nc4AATnF","packages":[{"ecosystem":"nuget","package_name":"jQuery","versions":[{"first_patched_version":"1.6.3","vulnerable_version_range":"\u003c 1.6.3"}],"purl":"pkg:nuget/jQuery","statistics":{"dependent_packages_count":290,"dependent_repos_count":1276,"downloads":263640954,"downloads_period":"total"},"affected_versions":["1.4.1","1.4.2","1.4.3","1.4.4","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2"],"unaffected_versions":["1.6.3","1.6.4","1.7.0","1.7.1","1.7.1.1","1.7.2","1.8.0","1.8.1","1.8.2","1.8.3","1.9.0","1.9.1","1.10.0","1.10.0.1","1.10.1","1.10.2","1.11.0","1.11.1","1.11.2","1.11.3","1.12.0","1.12.1","1.12.2","1.12.3","1.12.4","2.0.0","2.0.1","2.0.1.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","3.0.0","3.0.0.1","3.1.0","3.1.1","3.2.1","3.3.1","3.4.0","3.4.1","3.5.0","3.5.0.1","3.5.1","3.6.0","3.6.1","3.6.3","3.6.4","3.7.0","3.7.1"]},{"ecosystem":"npm","package_name":"jquery","versions":[{"first_patched_version":"1.6.3","vulnerable_version_range":"\u003c 1.6.3"}],"purl":"pkg:npm/jquery","statistics":{"dependent_packages_count":28173,"dependent_repos_count":998742,"downloads":60285686,"downloads_period":"last-month"},"affected_versions":["1.5.1","1.6.2"],"unaffected_versions":["1.6.3","1.7.2","1.7.3","1.8.2","1.8.3","1.9.1","1.11.0","1.11.1","1.11.2","1.11.3","1.12.0","1.12.1","1.12.2","1.12.3","1.12.4","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","3.0.0","3.1.0","3.1.1","3.2.0","3.2.1","3.3.0","3.3.1","3.4.0","3.4.1","3.5.0","3.5.1","3.6.0","3.6.1","3.6.2","3.6.3","3.6.4","3.7.0","3.7.1","4.0.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Nzl2LW1wM3YtcnJ3Nc4AATnF/related_packages","related_advisories":[{"uuid":"CPANSA-UR-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Zonemaster-GUI-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-YATT-Lite-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Plack-Debugger-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Resource-Pack-jQuery-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-MySQL-Admin-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Stardust-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-SockJS-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Kossy-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Sidef-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Squatting-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Zabbix-Reporter-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Yukki-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Yancy-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Ukigumo-Server-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-JS-jQuery-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-Yote-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"uuid":"CPANSA-App-Netdisco-2011-4969-jquery","source_kind":"cpansa","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"}]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJwcWotaDN2ai1wcWd3","url":"https://github.com/advisories/GHSA-2pqj-h3vj-pqgw","title":"Cross-Site Scripting in jquery","description":"Affected versions of `jquery` are vulnerable to cross-site scripting. This occurs because the main `jquery` function uses a regular expression to differentiate between HTML and selectors, but does not properly anchor the regular expression. The result is that `jquery` may interpret HTML as selectors when given certain inputs, allowing for client side code execution.\n\n## Proof of Concept\n```\n$(\"#log\").html(\n    $(\"element[attribute='\u003cimg src=\\\"x\\\" onerror=\\\"alert(1)\\\" /\u003e']\").html()\n);\n```\n\n\n\n\n## Recommendation\n\nUpdate to version 1.9.0 or later.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2020-09-01T16:41:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://bugs.jquery.com/ticket/11290","https://bugs.jquery.com/ticket/12531","https://bugs.jquery.com/ticket/6429","https://bugs.jquery.com/ticket/9521","https://nvd.nist.gov/vuln/detail/CVE-2017-16011","https://nvd.nist.gov/vuln/detail/CVE-2012-6708","https://github.com/jquery/jquery/commit/05531fc4080ae24070930d15ae0cea7ae056457d","https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://snyk.io/vuln/npm:jquery:20120206","http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html","http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html","http://packetstormsecurity.com/files/161972/Linksys-EA7500-2.0.8.194281-Cross-Site-Scripting.html","https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450223","https://research.insecurelabs.org/jquery/test/","https://web.archive.org/web/20200227132049/http://www.securityfocus.com/bid/102792","https://github.com/rails/jquery-rails/blob/v2.1.4/vendor/assets/javascripts/jquery.js#L59","https://github.com/rails/jquery-rails/blob/v2.2.0/vendor/assets/javascripts/jquery.js#L67","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2012-6708.yml","https://github.com/advisories/GHSA-2pqj-h3vj-pqgw"],"source_kind":"github","identifiers":["GHSA-2pqj-h3vj-pqgw","CVE-2012-6708"],"repository_url":"https://github.com/jquery/jquery","blast_radius":0.0,"created_at":"2022-12-21T16:12:47.310Z","updated_at":"2026-09-30T11:13:05.793Z","epss_percentage":0.08632,"epss_percentile":0.94858,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJwcWotaDN2ai1wcWd3","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJwcWotaDN2ai1wcWd3","packages":[{"ecosystem":"nuget","package_name":"jQuery","versions":[{"first_patched_version":"1.9.0","vulnerable_version_range":"\u003c= 1.8.3"}],"purl":"pkg:nuget/jQuery"},{"ecosystem":"maven","package_name":"org.webjars.npm:jquery","versions":[{"first_patched_version":"1.9.0","vulnerable_version_range":"\u003c= 1.8.3"}],"purl":null},{"ecosystem":"npm","package_name":"jquery","versions":[{"first_patched_version":"1.9.0","vulnerable_version_range":"\u003c= 1.8.3"}],"purl":"pkg:npm/jquery"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTJwcWotaDN2ai1wcWd3/related_packages","related_advisories":[{"uuid":"CPANSA-Zonemaster-GUI-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-YATT-Lite-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Plack-Debugger-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-UR-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Resource-Pack-jQuery-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-MySQL-Admin-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-SockJS-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Kossy-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Squatting-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-App-Netdisco-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Yukki-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Yancy-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Ukigumo-Server-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-JS-jQuery-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Yote-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Stardust-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Sidef-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"},{"uuid":"CPANSA-Zabbix-Reporter-2012-6708-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20120206"}]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpwY3EtY2d3Ni12NGo2","url":"https://github.com/advisories/GHSA-jpcq-cgw6-v4j6","title":"Potential XSS vulnerability in jQuery","description":"### Impact\nPassing HTML containing `\u003coption\u003e` elements from untrusted sources - even after sanitizing them - to one of jQuery's DOM manipulation methods (i.e. `.html()`, `.append()`, and others) may execute untrusted code.\n\n### Patches\nThis problem is patched in jQuery 3.5.0.\n\n### Workarounds\nTo workaround this issue without upgrading, use [DOMPurify](https://github.com/cure53/DOMPurify) with its `SAFE_FOR_JQUERY` option to sanitize the HTML string before passing it to a jQuery method.\n\n### References\nhttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/\n\n### For more information\nIf you have any questions or comments about this advisory, search for a relevant issue in [the jQuery repo](https://github.com/jquery/jquery/issues). If you don't find an answer, open a new issue.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2020-04-29T22:19:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N/E:H","references":["https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6","https://blog.jquery.com/2020/04/10/jquery-3-5-0-released","https://nvd.nist.gov/vuln/detail/CVE-2020-11023","https://www.drupal.org/sa-core-2020-002","https://www.debian.org/security/2020/dsa-4693","https://www.oracle.com/security-alerts/cpujul2020.html","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html","https://security.gentoo.org/glsa/202007-03","http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html","https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r9c5fda81e4bca8daee305b4c03283dddb383ab8428a151d4cb0b3b15@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/ra32c7103ded9041c7c1cb8c12c8d125a6b2f3f3270e2937ef8417fac@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/ra374bb0299b4aa3e04edde01ebc03ed6f90cf614dad40dd428ce8f72@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/ra3c9219fcb0b289e18e9ec5a5ebeaa5c17d6b79a201667675af6721c@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/ra406b3adfcffcb5ce8707013bdb7c35e3ffc2776a8a99022f15274c6@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rab82dd040f302018c85bd07d33f5604113573514895ada523c3401d9@%3Ccommits.hive.apache.org%3E","https://lists.apache.org/thread.html/radcb2aa874a79647789f3563fcbbceaf1045a029ee8806b59812a8ea@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rb25c3bc7418ae75cba07988dafe1b6912f76a9dd7d94757878320d61@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rb69b7d8217c1a6a2100247a5d06ce610836b31e3f5d73fc113ded8e7@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd38b4185a797b324c8dd940d9213cf99fcdc2dbf1fc5a63ba7dee8c9@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1ba79e564fe7efc56aef7c986106f1cf67a3427d08e997e088e7a93@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rf661a90a15da8da5922ba6127b3f5f8194d4ebec8855d60a0dd13248@%3Cdev.hive.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67@%3Cdev.flink.apache.org%3E","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html","https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6@%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330@%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef@%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16@%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494@%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c@%3Ccommits.felix.apache.org%3E","https://lists.apache.org/thread.html/r9e0bd31b7da9e7403478d22652b8760c946861f8ebd7bd750844898e@%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/rf0f8939596081d84be1ae6a91d6248b96a02d8388898c372ac807817@%3Cdev.felix.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c@%3Cissues.flink.apache.org%3E","https://www.tenable.com/security/tns-2021-02","https://lists.debian.org/debian-lts-announce/2021/03/msg00033.html","http://packetstormsecurity.com/files/162160/jQuery-1.0.3-Cross-Site-Scripting.html","https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108@%3Cissues.flink.apache.org%3E","https://www.tenable.com/security/tns-2021-10","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36@%3Cissues.flink.apache.org%3E","https://github.com/jquery/jquery/releases/tag/3.5.0","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2020-11023.yml","https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-565440","https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html","https://github.com/jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f77","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY","https://snyk.io/vuln/SNYK-JS-JQUERY-565129","https://security.netapp.com/advisory/ntap-20230725-0003","https://security.netapp.com/advisory/ntap-20200511-0006","https://jquery.com/upgrade-guide/3.5","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2020-23064.yml","https://github.com/rails/jquery-rails/blob/v4.4.0/vendor/assets/javascripts/jquery3.js#L6162","https://github.com/rails/jquery-rails/blob/v4.3.5/vendor/assets/javascripts/jquery3.js#L5979","https://github.com/rails/jquery-rails/blob/master/CHANGELOG.md#440","https://github.com/rails/jquery-rails/blob/master/CHANGELOG.md#410","https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rf0f8939596081d84be1ae6a91d6248b96a02d8388898c372ac807817%40%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/rf1ba79e564fe7efc56aef7c986106f1cf67a3427d08e997e088e7a93%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rf661a90a15da8da5922ba6127b3f5f8194d4ebec8855d60a0dd13248%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd38b4185a797b324c8dd940d9213cf99fcdc2dbf1fc5a63ba7dee8c9%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67%40%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/rb69b7d8217c1a6a2100247a5d06ce610836b31e3f5d73fc113ded8e7%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rb25c3bc7418ae75cba07988dafe1b6912f76a9dd7d94757878320d61%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/radcb2aa874a79647789f3563fcbbceaf1045a029ee8806b59812a8ea%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rab82dd040f302018c85bd07d33f5604113573514895ada523c3401d9%40%3Ccommits.hive.apache.org%3E","https://lists.apache.org/thread.html/ra406b3adfcffcb5ce8707013bdb7c35e3ffc2776a8a99022f15274c6%40%3Cissues.hive.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY","https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef%40%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330%40%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6%40%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36%40%3Cissues.flink.apache.org%3E","https://github.com/github/advisory-database/blob/99afa6fdeaf5d1d23e1021ff915a5e5dbc82c1f1/advisories/github-reviewed/2020/04/GHSA-jpcq-cgw6-v4j6/GHSA-jpcq-cgw6-v4j6.json#L20-L37","https://lists.apache.org/thread.html/ra3c9219fcb0b289e18e9ec5a5ebeaa5c17d6b79a201667675af6721c%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/ra374bb0299b4aa3e04edde01ebc03ed6f90cf614dad40dd428ce8f72%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/ra32c7103ded9041c7c1cb8c12c8d125a6b2f3f3270e2937ef8417fac%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/r9e0bd31b7da9e7403478d22652b8760c946861f8ebd7bd750844898e%40%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r9c5fda81e4bca8daee305b4c03283dddb383ab8428a151d4cb0b3b15%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c%40%3Ccommits.felix.apache.org%3E","https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494%40%3Cdev.felix.apache.org%3E","https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16%40%3Cdev.felix.apache.org%3E","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11023","https://github.com/advisories/GHSA-jpcq-cgw6-v4j6"],"source_kind":"github","identifiers":["GHSA-jpcq-cgw6-v4j6","CVE-2020-11023"],"repository_url":"https://github.com/jquery/jquery","blast_radius":0.0,"created_at":"2022-12-21T16:13:25.021Z","updated_at":"2026-09-30T11:12:03.324Z","epss_percentage":0.84887,"epss_percentile":0.99697,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpwY3EtY2d3Ni12NGo2","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpwY3EtY2d3Ni12NGo2","packages":[{"ecosystem":"maven","package_name":"org.webjars.npm:jquery","versions":[{"first_patched_version":"3.5.0","vulnerable_version_range":"\u003e= 1.0.3, \u003c 3.5.0"}],"purl":null},{"ecosystem":"nuget","package_name":"jQuery","versions":[{"first_patched_version":"3.5.0","vulnerable_version_range":"\u003e= 1.0.3, \u003c 3.5.0"}],"purl":"pkg:nuget/jQuery"},{"ecosystem":"rubygems","package_name":"jquery-rails","versions":[{"first_patched_version":"4.4.0","vulnerable_version_range":"\u003c 4.4.0"}],"purl":"pkg:gem/jquery-rails"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWpwY3EtY2d3Ni12NGo2/related_packages","related_advisories":[{"uuid":"CPANSA-YATT-Lite-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Plack-Debugger-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Resource-Pack-jQuery-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-MySQL-Admin-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Stardust-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-SockJS-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Sidef-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Squatting-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Zabbix-Reporter-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Zonemaster-GUI-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Yukki-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Yancy-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Ukigumo-Server-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-JS-jQuery-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Yote-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-UR-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-App-Netdisco-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"},{"uuid":"CPANSA-Kossy-2020-11023-jquery","source_kind":"cpansa","url":"https://jquery.com/upgrade-guide/3.5/"}]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZjM2otYzY0bS1xaGdx","url":"https://github.com/advisories/GHSA-6c3j-c64m-qhgq","title":"XSS in jQuery as used in Drupal, Backdrop CMS, and other products","description":"jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles `jQuery.extend(true, {}, ...)` because of `Object.prototype` pollution. If an unsanitized source object contained an enumerable `__proto__` property, it could extend the native `Object.prototype`.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2019-04-26T16:29:11.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2019-11358","https://backdropcms.org/security/backdrop-sa-core-2019-009","https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b","https://github.com/jquery/jquery/pull/4333","https://snyk.io/vuln/SNYK-JS-JQUERY-174006","https://www.drupal.org/sa-core-2019-006","https://access.redhat.com/errata/RHSA-2019:3023","https://access.redhat.com/errata/RHSA-2019:3024","https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc@%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844@%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f@%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7@%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205@%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6@%3Ccommits.roller.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r38f0d1aa3c923c22977fe7376508f030f22e22c1379fbb155bf29766@%3Cdev.syncope.apache.org%3E","https://lists.apache.org/thread.html/r7aac081cbddb6baa24b75e74abf0929bf309b176755a53e3ed810355@%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00006.html","https://lists.debian.org/debian-lts-announce/2019/05/msg00029.html","https://lists.debian.org/debian-lts-announce/2020/02/msg00024.html","https://www.debian.org/security/2019/dsa-4434","https://www.debian.org/security/2019/dsa-4460","https://www.synology.com/security/advisory/Synology_SA_19_19","https://www.tenable.com/security/tns-2019-08","https://www.tenable.com/security/tns-2020-02","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html","http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html","http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html","http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html","http://www.openwall.com/lists/oss-security/2019/06/03/2","https://lists.apache.org/thread.html/r2041a75d3fc09dec55adfd95d598b38d22715303f65c997c054844c9@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r2baacab6e0acb5a2092eb46ae04fd6c3e8277b4fd79b1ffb7f3254fa@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r41b5bfe009c845f67d4f68948cc9419ac2d62e287804aafd72892b08@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r7e8ebccb7c022e41295f6fdb7b971209b83702339f872ddd8cf8bf73@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r7d64895cc4dff84d0becfc572b20c0e4bf9bfa7b10c6f5f73e783734@%3Cdev.storm.apache.org%3E","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601","https://github.com/rails/jquery-rails/blob/master/CHANGELOG.md#434","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2019-11358.yml","https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450226","https://access.redhat.com/errata/RHBA-2019:1570","https://access.redhat.com/errata/RHSA-2019:1456","https://access.redhat.com/errata/RHSA-2019:2587","https://seclists.org/bugtraq/2019/Apr/32","https://seclists.org/bugtraq/2019/Jun/12","https://seclists.org/bugtraq/2019/May/18","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://seclists.org/fulldisclosure/2019/May/10","http://seclists.org/fulldisclosure/2019/May/11","http://seclists.org/fulldisclosure/2019/May/13","https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1","https://web.archive.org/web/20190824065237/http://www.securityfocus.com/bid/108023","https://github.com/django/django/commit/34ec52269ade54af31a021b12969913129571a3f","https://github.com/django/django/commit/95649bc08547a878cebfa1d019edec8cb1b80829","https://github.com/django/django/commit/baaf187a4e354bf3976c51e2c83a0d2f8ee6e6ad","https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html","http://www.securityfocus.com/bid/108023","https://blog.jquery.com/2019/04/10/jquery-3-4-0-released","https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205%40%3Ccommits.airflow.apache.org%3E","https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r2041a75d3fc09dec55adfd95d598b38d22715303f65c997c054844c9%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r2baacab6e0acb5a2092eb46ae04fd6c3e8277b4fd79b1ffb7f3254fa%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r38f0d1aa3c923c22977fe7376508f030f22e22c1379fbb155bf29766%40%3Cdev.syncope.apache.org%3E","https://lists.apache.org/thread.html/r41b5bfe009c845f67d4f68948cc9419ac2d62e287804aafd72892b08%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r7aac081cbddb6baa24b75e74abf0929bf309b176755a53e3ed810355%40%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/r7d64895cc4dff84d0becfc572b20c0e4bf9bfa7b10c6f5f73e783734%40%3Cdev.storm.apache.org%3E","https://lists.apache.org/thread.html/r7e8ebccb7c022e41295f6fdb7b971209b83702339f872ddd8cf8bf73%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d%40%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UOAZIFCSZ3ENEFOR5IXX6NFAD3HV7FA","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5IABSKTYZ5JUGL735UKGXL5YPRYOPUYI","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KYH3OAGR2RTCHRA5NOKX2TES7SNQMWGO","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QV3PKZC3PQCO3273HAT76PAQZFBEO4KP","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RLXRX23725JL366CNZGJZ7AQQB7LHQ6F","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZW27UCJ5CYFL4KFFFMYMIBNMIU2ALG5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UOAZIFCSZ3ENEFOR5IXX6NFAD3HV7FA","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5IABSKTYZ5JUGL735UKGXL5YPRYOPUYI","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KYH3OAGR2RTCHRA5NOKX2TES7SNQMWGO","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QV3PKZC3PQCO3273HAT76PAQZFBEO4KP","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLXRX23725JL366CNZGJZ7AQQB7LHQ6F","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WZW27UCJ5CYFL4KFFFMYMIBNMIU2ALG5","https://security.netapp.com/advisory/ntap-20190919-0001","https://www.djangoproject.com/weblog/2019/jun/03/security-releases","https://www.privacy-wise.com/mitigating-cve-2019-11358-in-old-versions-of-jquery","https://github.com/maximebf/php-debugbar/issues/447","https://github.com/maximebf/php-debugbar/commit/847216e60544258c881f2733d699bbcfeefac0fc","https://github.com/advisories/GHSA-6c3j-c64m-qhgq"],"source_kind":"github","identifiers":["GHSA-6c3j-c64m-qhgq","CVE-2019-11358"],"repository_url":"https://github.com/jquery/jquery","blast_radius":0.0,"created_at":"2022-12-21T16:13:30.327Z","updated_at":"2026-09-30T11:12:29.039Z","epss_percentage":0.87218,"epss_percentile":0.99727,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZjM2otYzY0bS1xaGdx","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZjM2otYzY0bS1xaGdx","packages":[{"ecosystem":"nuget","package_name":"jQuery","versions":[{"first_patched_version":"3.4.0","vulnerable_version_range":"\u003e= 1.1.4, \u003c 3.4.0"}],"purl":"pkg:nuget/jQuery"},{"ecosystem":"npm","package_name":"jquery","versions":[{"first_patched_version":"3.4.0","vulnerable_version_range":"\u003e= 1.1.4, \u003c 3.4.0"}],"purl":"pkg:npm/jquery"},{"ecosystem":"pypi","package_name":"django","versions":[{"first_patched_version":"2.2.2","vulnerable_version_range":"\u003e= 2.2a1, \u003c 2.2.2"},{"first_patched_version":"2.1.9","vulnerable_version_range":"\u003e= 2.0a1, \u003c 2.1.9"}],"purl":"pkg:pypi/django"},{"ecosystem":"rubygems","package_name":"jquery-rails","versions":[{"first_patched_version":"4.3.4","vulnerable_version_range":"\u003c 4.3.4"}],"purl":"pkg:gem/jquery-rails"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZjM2otYzY0bS1xaGdx/related_packages","related_advisories":[{"uuid":"CPANSA-Zonemaster-GUI-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Plack-Debugger-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-UR-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Resource-Pack-jQuery-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-MySQL-Admin-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Stardust-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Kossy-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Sidef-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Squatting-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-App-Netdisco-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Zabbix-Reporter-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Yancy-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Ukigumo-Server-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-JS-jQuery-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Yote-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-YATT-Lite-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-SockJS-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"},{"uuid":"CPANSA-Yukki-2019-11358-jquery","source_kind":"cpansa","url":"https://www.drupal.org/sa-core-2019-006"}]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd2NjctcThyci1ncmpw","url":"https://github.com/advisories/GHSA-wv67-q8rr-grjp","title":"Duplicate Advisory: Prototype Pollution in jquery","description":"## Duplicate Advisory\nThis advisory is a duplicate of [GHSA-6c3j-c64m-qhgq](https://github.com/advisories/GHSA-6c3j-c64m-qhgq). This link is maintained to preserve external references.\n\n## Original Description\nVersions of `jquery`  prior to 3.4.0 are vulnerable to Prototype Pollution. The extend() method allows an attacker to modify the prototype for `Object` causing changes in properties that will exist on all objects.\n\n## Recommendation\nUpgrade to version 3.4.0 or later.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2019-04-23T15:59:10.000Z","withdrawn_at":"2019-04-26T14:50:56.000Z","classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-5428","https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/","https://github.com/jquery/jquery/pull/4333","https://hackerone.com/reports/454365","https://www.npmjs.com/advisories/796","https://github.com/advisories/GHSA-wv67-q8rr-grjp"],"source_kind":"github","identifiers":["GHSA-wv67-q8rr-grjp","CVE-2019-5428"],"repository_url":"https://github.com/jquery/jquery","blast_radius":0.0,"created_at":"2022-12-21T16:13:30.388Z","updated_at":"2026-09-30T11:12:03.323Z","epss_percentage":0.00241,"epss_percentile":0.63534,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd2NjctcThyci1ncmpw","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd2NjctcThyci1ncmpw","packages":[{"ecosystem":"maven","package_name":"org.webjars.npm:jquery","versions":[{"first_patched_version":"3.4.0","vulnerable_version_range":"\u003c 3.4.0"}],"purl":null},{"ecosystem":"nuget","package_name":"jquery","versions":[{"first_patched_version":"3.4.0","vulnerable_version_range":"\u003c 3.4.0"}],"purl":"pkg:nuget/jquery"},{"ecosystem":"npm","package_name":"jquery","versions":[{"first_patched_version":"3.4.0","vulnerable_version_range":"\u003c 3.4.0"}],"purl":"pkg:npm/jquery"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd2NjctcThyci1ncmpw/related_packages","related_advisories":[{"uuid":"CPANSA-YATT-Lite-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Plack-Debugger-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-UR-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Resource-Pack-jQuery-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Stardust-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-SockJS-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Sidef-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-App-Netdisco-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Zonemaster-GUI-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Yancy-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Ukigumo-Server-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-JS-jQuery-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Yote-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-MySQL-Admin-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Kossy-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Yukki-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Squatting-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"},{"uuid":"CPANSA-Zabbix-Reporter-2019-5428-jquery","source_kind":"cpansa","url":"https://security.snyk.io/vuln/SNYK-JS-JQUERY-174006"}]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1ocHAtODc1dy05Y3B2","url":"https://github.com/advisories/GHSA-mhpp-875w-9cpv","title":"Denial of Service in jquery","description":"Affected versions of `jquery` use a lowercasing logic on attribute names. When given a boolean attribute with a name that contains uppercase characters, `jquery` enters into an infinite recursion loop, exceeding the call stack limit, and resulting in a denial of service condition.\n\n\n## Recommendation\n\nUpdate to version 3.0.0 or later.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2018-01-22T13:32:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2016-10707","https://github.com/jquery/jquery/issues/3133","https://github.com/advisories/GHSA-mhpp-875w-9cpv","https://www.npmjs.com/advisories/330","https://github.com/jquery/jquery/pull/3134","https://snyk.io/vuln/npm:jquery:20160529","https://github.com/jquery/jquery/issues/3133#issuecomment-358978489","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2016-10707.yml"],"source_kind":"github","identifiers":["GHSA-mhpp-875w-9cpv","CVE-2016-10707"],"repository_url":"https://github.com/jquery/jquery","blast_radius":0.0,"created_at":"2022-12-21T16:11:56.214Z","updated_at":"2026-09-30T11:12:02.127Z","epss_percentage":0.02886,"epss_percentile":0.85507,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1ocHAtODc1dy05Y3B2","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1ocHAtODc1dy05Y3B2","packages":[{"ecosystem":"nuget","package_name":"jQuery","versions":[{"first_patched_version":"3.0.0","vulnerable_version_range":"= 3.0.0-rc.1"}],"purl":"pkg:nuget/jQuery","statistics":{"dependent_packages_count":290,"dependent_repos_count":1276,"downloads":263640954,"downloads_period":"total"},"affected_versions":[],"unaffected_versions":["1.4.1","1.4.2","1.4.3","1.4.4","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.7.0","1.7.1","1.7.1.1","1.7.2","1.8.0","1.8.1","1.8.2","1.8.3","1.9.0","1.9.1","1.10.0","1.10.0.1","1.10.1","1.10.2","1.11.0","1.11.1","1.11.2","1.11.3","1.12.0","1.12.1","1.12.2","1.12.3","1.12.4","2.0.0","2.0.1","2.0.1.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","3.0.0","3.0.0.1","3.1.0","3.1.1","3.2.1","3.3.1","3.4.0","3.4.1","3.5.0","3.5.0.1","3.5.1","3.6.0","3.6.1","3.6.3","3.6.4","3.7.0","3.7.1"]},{"ecosystem":"npm","package_name":"jquery","versions":[{"first_patched_version":"3.0.0","vulnerable_version_range":"= 3.0.0-rc.1"}],"purl":"pkg:npm/jquery","statistics":{"dependent_packages_count":28173,"dependent_repos_count":998742,"downloads":60285686,"downloads_period":"last-month"},"affected_versions":[],"unaffected_versions":["1.5.1","1.6.2","1.6.3","1.7.2","1.7.3","1.8.2","1.8.3","1.9.1","1.11.0","1.11.1","1.11.2","1.11.3","1.12.0","1.12.1","1.12.2","1.12.3","1.12.4","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","3.0.0","3.1.0","3.1.1","3.2.0","3.2.1","3.3.0","3.3.1","3.4.0","3.4.1","3.5.0","3.5.1","3.6.0","3.6.1","3.6.2","3.6.3","3.6.4","3.7.0","3.7.1","4.0.0"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1ocHAtODc1dy05Y3B2/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJteGctNzNnZy00cDk4","url":"https://github.com/advisories/GHSA-rmxg-73gg-4p98","title":"Cross-Site Scripting (XSS) in jquery","description":"Affected versions of `jquery` interpret `text/javascript` responses from cross-origin ajax requests, and automatically execute the contents in `jQuery.globalEval`, even when the ajax request doesn't contain the `dataType` option.\n\n\n## Recommendation\n\nUpdate to version 3.0.0 or later.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2018-01-22T13:32:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2015-9251","https://github.com/jquery/jquery/issues/2432","https://github.com/jquery/jquery/pull/2588","https://github.com/jquery/jquery/commit/b078a62013782c7424a4a61a240c23c4c0b42614","https://github.com/jquery/jquery/pull/2588/commits/c254d308a7d3f1eac4d0b42837804cfffcba4bb2","https://github.com/jquery/jquery/commit/f60729f3903d17917dc351f3ac87794de379b0cc","https://access.redhat.com/errata/RHSA-2020:0481","https://access.redhat.com/errata/RHSA-2020:0729","https://ics-cert.us-cert.gov/advisories/ICSA-18-212-04","https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601","https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731@%3Cdev.flink.apache.org%3E","https://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49@%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2@%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854@%3Cuser.flink.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6@%3Ccommits.roller.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://seclists.org/bugtraq/2019/May/18","https://security.netapp.com/advisory/ntap-20210108-0004/","https://snyk.io/vuln/npm:jquery:20150627","https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec126.pdf","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.tenable.com/security/tns-2019-08","http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html","http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html","http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html","http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html","http://seclists.org/fulldisclosure/2019/May/10","http://seclists.org/fulldisclosure/2019/May/11","http://seclists.org/fulldisclosure/2019/May/13","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450227","https://github.com/jquery/jquery/issues/2432#issuecomment-403761229","https://github.com/rails/jquery-rails/blob/master/CHANGELOG.md#420","https://github.com/rails/jquery-rails/blob/v4.2.0/vendor/assets/javascripts/jquery3.js#L9377","https://web.archive.org/web/20200227030101/http://www.securityfocus.com/bid/105658","https://github.com/rails/jquery-rails/releases/tag/v4.2.0","https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2015-9251.yml","https://github.com/advisories/GHSA-rmxg-73gg-4p98"],"source_kind":"github","identifiers":["GHSA-rmxg-73gg-4p98","CVE-2015-9251"],"repository_url":"https://github.com/jquery/jquery","blast_radius":0.0,"created_at":"2022-12-21T16:13:37.495Z","updated_at":"2026-09-30T09:13:56.324Z","epss_percentage":0.29726,"epss_percentile":0.98113,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJteGctNzNnZy00cDk4","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJteGctNzNnZy00cDk4","packages":[{"ecosystem":"maven","package_name":"org.webjars.npm:jquery","versions":[{"first_patched_version":"3.0.0","vulnerable_version_range":"\u003e= 1.12.3, \u003c 3.0.0"},{"first_patched_version":"1.12.2","vulnerable_version_range":"\u003c 1.12.2"}],"purl":null},{"ecosystem":"rubygems","package_name":"jquery-rails","versions":[{"first_patched_version":"4.2.0","vulnerable_version_range":"\u003c 4.2.0"}],"purl":"pkg:gem/jquery-rails"},{"ecosystem":"npm","package_name":"jquery","versions":[{"first_patched_version":"3.0.0","vulnerable_version_range":"\u003e= 1.12.3, \u003c 3.0.0"},{"first_patched_version":"1.12.2","vulnerable_version_range":"\u003c 1.12.2"}],"purl":"pkg:npm/jquery"},{"ecosystem":"nuget","package_name":"jQuery","versions":[{"first_patched_version":"3.0.0","vulnerable_version_range":"\u003e= 1.12.3, \u003c 3.0.0"},{"first_patched_version":"1.12.2","vulnerable_version_range":"\u003c 1.12.2"}],"purl":"pkg:nuget/jQuery"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJteGctNzNnZy00cDk4/related_packages","related_advisories":[{"uuid":"CPANSA-Zonemaster-GUI-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-YATT-Lite-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Plack-Debugger-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-UR-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-MySQL-Admin-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Stardust-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-SockJS-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Kossy-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Sidef-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Squatting-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-App-Netdisco-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Zabbix-Reporter-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Ukigumo-Server-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-JS-jQuery-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Yote-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Yukki-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Yancy-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"uuid":"CPANSA-Resource-Pack-jQuery-2015-9251-jquery","source_kind":"cpansa","url":"https://snyk.io/vuln/npm:jquery:20150627"}]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/nuget/jquery","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nuget/jquery","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nuget/jquery/dependencies","status":null,"funding_links":[],"critical":false,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nuget.org/packages/jquery/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nuget.org/packages/jquery/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nuget.org/packages/jquery/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nuget.org/packages/jquery/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nuget.org/packages/jquery/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nuget.org/packages/jquery/codemeta","maintainers":[{"uuid":"aspnet","login":"aspnet","name":null,"email":null,"url":null,"packages_count":1202,"html_url":"https://www.nuget.org/profiles/aspnet","role":null,"created_at":"2022-11-15T17:59:40.317Z","updated_at":"2022-11-15T17:59:40.317Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nuget.org/maintainers/aspnet/packages"},{"uuid":"outercurve","login":"outercurve","name":null,"email":null,"url":null,"packages_count":22,"html_url":"https://www.nuget.org/profiles/outercurve","role":null,"created_at":"2022-11-15T17:59:40.325Z","updated_at":"2022-11-15T17:59:40.325Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nuget.org/maintainers/outercurve/packages"}]}