{"id":"GHSA-rmxg-73gg-4p98","summary":"Cross-Site Scripting (XSS) in jquery","details":"Affected versions of `jquery` interpret `text/javascript` responses from cross-origin ajax requests, and automatically execute the contents in `jQuery.globalEval`, even when the ajax request doesn't contain the `dataType` option.\n\n\n## Recommendation\n\nUpdate to version 3.0.0 or later.","aliases":["CVE-2015-9251"],"modified":"2024-03-10T05:19:17.737001Z","published":"2018-01-22T13:32:06Z","database_specific":{"nvd_published_at":"2018-01-18T23:29:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:55:10Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-9251"},{"type":"WEB","url":"https://github.com/jquery/jquery/issues/2432"},{"type":"WEB","url":"https://github.com/jquery/jquery/issues/2432#issuecomment-403761229"},{"type":"WEB","url":"https://github.com/jquery/jquery/pull/2588"},{"type":"WEB","url":"https://github.com/jquery/jquery/pull/2588/commits/c254d308a7d3f1eac4d0b42837804cfffcba4bb2"},{"type":"WEB","url":"https://github.com/jquery/jquery/commit/b078a62013782c7424a4a61a240c23c4c0b42614"},{"type":"WEB","url":"https://github.com/jquery/jquery/commit/f60729f3903d17917dc351f3ac87794de379b0cc"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2020:0481"},{"type":"WEB","url":"https://seclists.org/bugtraq/2019/May/18"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210108-0004"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450227"},{"type":"WEB","url":"https://snyk.io/vuln/npm:jquery:20150627"},{"type":"WEB","url":"https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec126.pdf"},{"type":"WEB","url":"https://web.archive.org/web/20200227030101/http://www.securityfocus.com/bid/105658"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2019-08"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2020:0729"},{"type":"PACKAGE","url":"https://github.com/jquery/jquery"},{"type":"WEB","url":"https://github.com/rails/jquery-rails/blob/master/CHANGELOG.md#420"},{"type":"WEB","url":"https://github.com/rails/jquery-rails/blob/v4.2.0/vendor/assets/javascripts/jquery3.js#L9377"},{"type":"WEB","url":"https://github.com/rails/jquery-rails/releases/tag/v4.2.0"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2015-9251.yml"},{"type":"WEB","url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-212-04"},{"type":"WEB","url":"https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601"},{"type":"WEB","url":"https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731@%3Cdev.flink.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49@%3Cuser.flink.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2@%3Cuser.flink.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854@%3Cuser.flink.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6@%3Ccommits.roller.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2019/May/10"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2019/May/11"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2019/May/13"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"}],"affected":[{"package":{"name":"jquery","ecosystem":"npm","purl":"pkg:npm/jquery"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.12.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-rmxg-73gg-4p98/GHSA-rmxg-73gg-4p98.json"}},{"package":{"name":"jQuery","ecosystem":"NuGet","purl":"pkg:nuget/jQuery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.2"}]}],"versions":["1.10.0","1.10.0.1","1.10.1","1.10.2","1.11.0","1.11.1","1.11.2","1.11.3","1.12.0","1.12.1","1.4.1","1.4.2","1.4.3","1.4.4","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.7.0","1.7.1","1.7.1.1","1.7.2","1.8.0","1.8.1","1.8.2","1.8.3","1.9.0","1.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-rmxg-73gg-4p98/GHSA-rmxg-73gg-4p98.json"}},{"package":{"name":"jQuery","ecosystem":"NuGet","purl":"pkg:nuget/jQuery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.12.3"},{"fixed":"3.0.0"}]}],"versions":["1.12.3","1.12.4","2.0.0","2.0.1","2.0.1.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-rmxg-73gg-4p98/GHSA-rmxg-73gg-4p98.json"}},{"package":{"name":"jquery","ecosystem":"npm","purl":"pkg:npm/jquery"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.12.3"},{"fixed":"3.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-rmxg-73gg-4p98/GHSA-rmxg-73gg-4p98.json"}},{"package":{"name":"jquery-rails","ecosystem":"RubyGems","purl":"pkg:gem/jquery-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.0"}]}],"versions":["0.1.1","0.1.2","0.1.3","0.2","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","1.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.0.rc","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.3.0","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","4.0.0","4.0.0.beta1","4.0.0.beta2","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.1.0","4.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-rmxg-73gg-4p98/GHSA-rmxg-73gg-4p98.json"}},{"package":{"name":"org.webjars.npm:jquery","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/jquery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.2"}]}],"versions":["1.11.0","1.11.1","1.11.3","1.12.1","1.7.2","1.7.3","1.8.2","1.8.3","1.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-rmxg-73gg-4p98/GHSA-rmxg-73gg-4p98.json"}},{"package":{"name":"org.webjars.npm:jquery","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/jquery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.12.3"},{"fixed":"3.0.0"}]}],"versions":["1.12.3","1.12.4","2.1.0","2.1.1","2.1.1-rc1","2.1.1-rc2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","3.0.0-alpha1","3.0.0-beta1","3.0.0-rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/01/GHSA-rmxg-73gg-4p98/GHSA-rmxg-73gg-4p98.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}