This repository has been archived by the owner on Jun 8, 2020. It is now read-only.
CVE-2011-4969 (Medium) detected in jquery-1.4.4.min.js #78
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2011-4969 - Medium Severity Vulnerability
Vulnerable Library - jquery-1.4.4.min.js
JavaScript library for DOM operations
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jquery/1.4.4/jquery.min.js
Path to dependency file: /tmp/ws-scm/Angular-7-learning-Udemy/game-control-assignment/node_modules/selenium-webdriver/lib/test/data/mousePositionTracker.html
Path to vulnerable library: /Angular-7-learning-Udemy/game-control-assignment/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/servicesExample/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/directives-example/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/forms-example/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/pipes-example/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/observables-example/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/assignment-project/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/forms-reactive-assignment/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/routing-example/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/http-example/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/shopping-recipe-course/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js,/Angular-7-learning-Udemy/forms-reactive/node_modules/selenium-webdriver/lib/test/data/js/jquery-1.4.4.min.js
Dependency Hierarchy:
Found in HEAD commit: b521d303214c9393a64f26b4a521fcbb4f0a5abd
Vulnerability Details
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.
Publish Date: 2013-03-08
URL: CVE-2011-4969
CVSS 2 Score Details (4.3)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2011-4969
Release Date: 2013-03-08
Fix Resolution: 1.6.3
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: