This repository has been archived by the owner on May 6, 2021. It is now read-only.
CVE-2011-4969 (Medium) detected in jquery-1.4.4.min.js #73
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2011-4969 - Medium Severity Vulnerability
Vulnerable Library - jquery-1.4.4.min.js
JavaScript library for DOM operations
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jquery/1.4.4/jquery.min.js
Path to dependency file: angular2-book-list/node_modules/selenium-webdriver/lib/test/data/droppableItems.html
Path to vulnerable library: angular2-book-list/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js
Dependency Hierarchy:
Found in HEAD commit: ee9bfd47f260e9ec9e2c8153b723f8d50814f465
Found in base branch: master
Vulnerability Details
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.
Publish Date: 2013-03-08
URL: CVE-2011-4969
CVSS 2 Score Details (4.3)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2011-4969
Release Date: 2013-03-08
Fix Resolution: 1.6.3
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: