Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jquery 3.3.1 Found in vue-owl-carousel #59

Open
abhinaw004 opened this issue Jan 18, 2023 · 0 comments
Open

jquery 3.3.1 Found in vue-owl-carousel #59

abhinaw004 opened this issue Jan 18, 2023 · 0 comments

Comments

@abhinaw004
Copy link

jquery 3.3.1 Found in /js/chunk-d6efb0b4.7b5ee9ce.js _____Vulnerability info:mediumCVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution123mediumCVE-2020-11022 Regex in its jQuery.htmlPrefilter sometimes may introduce XSS1mediumCVE-2020-11023 Regex in its jQuery.htmlPrefilter sometimes may introduce XSS medium CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution 123 medium CVE-2020-11022 Regex in its jQuery.htmlPrefilter sometimes may introduce XSS 1 medium CVE-2020-11023 Regex in its jQuery.htmlPrefilter sometimes may introduce XSS
medium CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution 123
medium CVE-2020-11022 Regex in its jQuery.htmlPrefilter sometimes may introduce XSS 1
medium CVE-2020-11023 Regex in its jQuery.htmlPrefilter sometimes may introduce XSS
jquery 3.3.1 Found in js/chunk-d6efb0b4.7b5ee9ce.js _____Vulnerability info: medium CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution [1](https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/)[2](https://nvd.nist.gov/vuln/detail/CVE-2019-11358)[3](https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b) medium CVE-2020-11022 Regex in its jQuery.htmlPrefilter sometimes may introduce XSS [1](https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/) medium CVE-2020-11023 Regex in its jQuery.htmlPrefilter sometimes may introduce XSS
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant