{"id":"GHSA-579v-mp3v-rrw5","summary":"jQuery vulnerable to Cross-Site Scripting (XSS)","details":"Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.","aliases":["CVE-2011-4969"],"modified":"2026-01-15T02:22:49.784258Z","published":"2022-05-14T01:09:51Z","database_specific":{"nvd_published_at":"2013-03-08T22:55:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-09-12T14:46:34Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4969"},{"type":"WEB","url":"https://github.com/jquery/jquery/commit/db9e023e62c1ff5d8f21ed9868ab6878da2005e9"},{"type":"PACKAGE","url":"https://github.com/jquery/jquery"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2011-4969.yml"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20190416-0007"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450224"},{"type":"WEB","url":"http://blog.jquery.com/2011/09/01/jquery-1-6-3-released"},{"type":"WEB","url":"http://blog.mindedsecurity.com/2011/07/jquery-is-sink.html"},{"type":"WEB","url":"http://bugs.jquery.com/ticket/9521"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/01/31/3"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-1722-1"}],"affected":[{"package":{"name":"jquery","ecosystem":"npm","purl":"pkg:npm/jquery"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.6.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-579v-mp3v-rrw5/GHSA-579v-mp3v-rrw5.json"}},{"package":{"name":"jQuery","ecosystem":"NuGet","purl":"pkg:nuget/jQuery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.3"}]}],"versions":["1.4.1","1.4.2","1.4.3","1.4.4","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-579v-mp3v-rrw5/GHSA-579v-mp3v-rrw5.json"}},{"package":{"name":"jquery-rails","ecosystem":"RubyGems","purl":"pkg:gem/jquery-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.16"}]}],"versions":["0.1.1","0.1.2","0.1.3","0.2","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","1.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.0.rc"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-579v-mp3v-rrw5/GHSA-579v-mp3v-rrw5.json"}},{"package":{"name":"org.webjars.npm:jquery","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/jquery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-579v-mp3v-rrw5/GHSA-579v-mp3v-rrw5.json"}}],"schema_version":"1.9.0"}