CVE-2020-7656
published 2020-05-19CVE-2020-7656: jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "" HTML tags that contain a…
PriorityP340medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
6.27%
92.8th percentile
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "" HTML tags that contain a whitespace character, i.e: "", which results in the enclosed script logic to be executed.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jquery | jquery | < 1.9.0 | 1.9.0 |
| jquery | jquery | — | — |
| jquery | jquery | >= 1.2.1 < 1.9.0 | 1.9.0 |
| jquery | jquery | >= 1.2.1 < 1.9.0 | 1.9.0 |
| juniper | junos | — | — |
| netapp | oncommand_system_manager | 3.0.0 – 3.1.3 | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle PeopleSoft Risk Matrix: PeopleSoft CDA (jQuery) — CVE-2020-7656
vendor_oracle·2022-07-15·CVSS 6.1
CVE-2020-7656 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: PeopleSoft CDA (jQuery) — CVE-2020-7656
Oracle Oracle PeopleSoft Risk Matrix: PeopleSoft CDA (jQuery) vulnerability
CVE: CVE-2020-7656
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
CISA ICS
Pepperl+Fuchs WirelessHART-Gateway
cisa_ics·2022-04-07·CVSS 7.5
[HIGH] Pepperl+Fuchs WirelessHART-Gateway
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Pepperl+Fuchs WirelessHART-Gateway
Last RevisedApril 07, 2022
Alert CodeICSA-22-097-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Pepperl+Fuchs
- Equipment: WirelessHART-Gateway
- Vulnerabilities: Use of Hard-coded Credentials, Uncontrolled Resource Consumption, Reliance on Reverse DNS Resolution for a Security-critical Action, Path Traversal, Cross-site Scripting, Exposure of Sensitive Information to an Unauthorized Actor, Cleartext Storage of Sensitive Information in a Cookie, HTTP Request Smuggling, Sensitive Co
Red Hat
jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces
vendor_redhat·2020-05-19·CVSS 6.1
CVE-2020-7656 [MEDIUM] CWE-79 jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces
jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "" HTML tags that contain a whitespace character, i.e: "", which results in the enclosed script logic to be executed.
A flaw was found in jquery in versions prior to 1.9.0. A cross-site scripting attack is possible as the load method fails to recognize and remove "" HTML tags that contain a whitespace character which results in the enclosed script logic to be executed. The highest threat from this vulnerability is to data confidentiality and integrity.
Statement: Red Hat Enterprise Linux version 6, 7 and 8 ship a vulnerable version of JQuery in the `pcs` component. However the vulnerable has n
OSV
Cross-Site Scripting in jquery
osv·2020-05-20
CVE-2020-7656 [MEDIUM] Cross-Site Scripting in jquery
Cross-Site Scripting in jquery
Versions of `jquery` prior to 1.9.0 are vulnerable to Cross-Site Scripting. The load method fails to recognize and remove `` HTML tags that contain a whitespace character, i.e: ``, which results in the enclosed script logic to be executed. This allows attackers to execute arbitrary JavaScript in a victim's browser.
## Recommendation
Upgrade to version 1.9.0 or later.
GHSA
Cross-Site Scripting in jquery
ghsa·2020-05-20
CVE-2020-7656 [MEDIUM] CWE-79 Cross-Site Scripting in jquery
Cross-Site Scripting in jquery
Versions of `jquery` prior to 1.9.0 are vulnerable to Cross-Site Scripting. The load method fails to recognize and remove `` HTML tags that contain a whitespace character, i.e: ``, which results in the enclosed script logic to be executed. This allows attackers to execute arbitrary JavaScript in a victim's browser.
## Recommendation
Upgrade to version 1.9.0 or later.
OSV
CVE-2020-7656: jquery prior to 1
osv·2020-05-19·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656: jquery prior to 1
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "" HTML tags that contain a whitespace character, i.e: "", which results in the enclosed script logic to be executed.
No detection rules found.
Bugzilla
CVE-2020-7656 pcs: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-10-08·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 pcs: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 pcs: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2020-7656 rubygem-jquery-rails: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 rubygem-jquery-rails: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 rubygem-jquery-rails: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2020-7656 js-jquery2: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 js-jquery2: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 js-jquery2: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2020-7656 python-XStatic-jQuery: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-7]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-XStatic-jQuery: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-7]
CVE-2020-7656 python-XStatic-jQuery: jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2020-7656 python-tw-jquery: jQuery: allows XSS via the load method [epel-6]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-tw-jquery: jQuery: allows XSS via the load method [epel-6]
CVE-2020-7656 python-tw-jquery: jQuery: allows XSS via the load method [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fe
Bugzilla
CVE-2020-7656 jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces
CVE-2020-7656 jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "" HTML tags that contain a whitespace character, i.e: "", which results in the enclosed script logic to be executed.
https://security.netapp.com/advisory/ntap-20200528-0001/
https://snyk.io/vuln/SNYK-JS-JQUERY-569619
Discussion:
Created drupal7 tracking bugs for this issue:
Affects: epel-all [bug 1850138]
Affects: fedora-all [bug 1850136]
Created js-jquery tracking bugs for this issue:
Affects: epel-7 [bug 1850123]
Affects: fedora-all [bug 1850127]
Created js-jquery1 tracking bugs for this issue:
Affects: epel-7 [bug 1850134]
Affects: fedora-all [bug 1850133]
Created j
Bugzilla
CVE-2020-7656 drupal7: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 drupal7: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 drupal7: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2020-7656 js-jquery1: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 js-jquery1: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 js-jquery1: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2020-7656 python-tw2-jquery: jQuery: allows XSS via the load method [epel-6]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-tw2-jquery: jQuery: allows XSS via the load method [epel-6]
CVE-2020-7656 python-tw2-jquery: jQuery: allows XSS via the load method [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'f
Bugzilla
CVE-2020-7656 js-jquery: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 js-jquery: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 js-jquery: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2020-7656 python-XStatic-jQuery: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [openstack-rdo]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-XStatic-jQuery: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [openstack-rdo]
CVE-2020-7656 python-XStatic-jQuery: jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
D
Bugzilla
CVE-2020-7656 python-XStatic-jQuery: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-XStatic-jQuery: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 python-XStatic-jQuery: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2020-7656 js-jquery: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-7]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 js-jquery: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-7]
CVE-2020-7656 js-jquery: jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the followi
Bugzilla
CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [epel-7]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [epel-7]
CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for
Bugzilla
CVE-2020-7656 python-tw2-jquery: jQuery: allows XSS via the load method [fedora-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-tw2-jquery: jQuery: allows XSS via the load method [fedora-all]
CVE-2020-7656 python-tw2-jquery: jQuery: allows XSS via the load method [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2020-7656 js-jquery1: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-7]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 js-jquery1: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-7]
CVE-2020-7656 js-jquery1: jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the follow
Bugzilla
CVE-2020-7656 python-tw2-jquery: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-7]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-tw2-jquery: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-7]
CVE-2020-7656 python-tw2-jquery: jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the
Bugzilla
CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [openstack-rdo]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [openstack-rdo]
CVE-2020-7656 python-XStatic-jquery-ui: jQuery: allows XSS via the load method [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
This is a bug in jq
Bugzilla
CVE-2020-7656 drupal7: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-all]
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 drupal7: jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces [epel-all]
CVE-2020-7656 drupal7: jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
https://security.netapp.com/advisory/ntap-20200528-0001/https://snyk.io/vuln/SNYK-JS-JQUERY-569619https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1?language=en_UShttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://security.netapp.com/advisory/ntap-20200528-0001/https://snyk.io/vuln/SNYK-JS-JQUERY-569619https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1?language=en_UShttps://www.oracle.com/security-alerts/cpujul2022.html
2020-05-19
Published