Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Feb 2, 2017 | Feb 1, 2017 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 26, 2016 | Mar 8, 2013 |
| Jenkins 2017 02 01 | — | Upgrade Jenkins to version 2.44Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest versionUpgrade Jenkins LTS to version 2.32.2 | Nov 13, 2017 | Mar 8, 2013 |
| Jquery | — | Upgrade jQuery to version 1.6.2 | Jan 23, 2014 | Mar 8, 2013 |
| Oracle Solaris | — | Upgrade consolidation/osnet/osnet-incorporation to version 11.4-11.4.1.0.1.4.0 on Solaris 11.4 | Oct 19, 2018 | Mar 8, 2013 |
| Ubuntu | — | Upgrade libjs-jquery | Nov 8, 2024 | Mar 8, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub