Back to Database
Status published
Medium
CVE-2015-9251
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks...
Vulnerability Description
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-9251
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/105658
- https://seclists.org/bugtraq/2019/May/18
- http://seclists.org/fulldisclosure/2019/May/11
- http://seclists.org/fulldisclosure/2019/May/10
- http://seclists.org/fulldisclosure/2019/May/13
- https://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org%3E
- https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%3E
- https://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org%3E
- https://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org%3E
- https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
- https://access.redhat.com/errata/RHSA-2020:0481
- https://access.redhat.com/errata/RHSA-2020:0729
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html
- https://www.oracle.com/security-alerts/cpuapr2020.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://github.com/jquery/jquery/issues/2432
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec126.pdf
- https://github.com/jquery/jquery/pull/2588/commits/c254d308a7d3f1eac4d0b42837804cfffcba4bb2
- https://snyk.io/vuln/npm:jquery:20150627
- https://github.com/jquery/jquery/pull/2588
- https://ics-cert.us-cert.gov/advisories/ICSA-18-212-04
- https://github.com/jquery/jquery/commit/f60729f3903d17917dc351f3ac87794de379b0cc
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
- http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.tenable.com/security/tns-2019-08
- https://www.oracle.com/security-alerts/cpujan2020.html
- http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
- https://security.netapp.com/advisory/ntap-20210108-0004/
More from jquery
View All →CVE-2022-31160
jQuery UI contains potential XSS vulnerability when refreshing a checkboxradio with an HTML-like initial text label
Medium
6.1
CVE-2021-41184
XSS in the `of` option of the `.position()` util
Medium
6.5
CVE-2021-41183
XSS in `*Text` options of the Datepicker widget
Medium
6.5
CVE-2021-41182
XSS in the `altField` option of the Datepicker widget
Medium
6.5
CVE-2020-11023
Potential XSS vulnerability in jQuery
Medium
6.9
Affected Vendor
jquery
View all reports →Affected Software
jquery, agile product lifecycle management for process, banking platform, business process management suite, communications converged application server, communications interactive session recorder, communications services gatekeeper, communications webrtc session controller, endeca information discovery studio, enterprise manager ops center, enterprise operations monitor, financial services analytical applications infrastructure, financial services asset liability management, financial services data integration hub, financial services funds transfer pricing, financial services hedge management and ifrs valuations, financial services liquidity risk management, financial services loan loss forecasting and provisioning, financial services market risk measurement and management, financial services profitability management, financial services reconciliation framework, fusion middleware mapviewer, healthcare foundation, healthcare translational research, hospitality cruise fleet management, hospitality guest access, hospitality materials control, hospitality reporting and analytics, insurance insbridge rating and underwriting, jd edwards enterpriseone tools, jdeveloper, oss support tools, peoplesoft enterprise peopletools, primavera gateway, primavera unifier, real-time scheduler, retail allocation, retail customer insights, retail invoice matching, retail sales audit, retail workforce management software, service bus, siebel ui framework, utilities framework, utilities mobile workforce management, webcenter sites, weblogic server
Vulnerable Versions:
0, 6.2.0.0, 6.2.1.0, 6.2.2.0, 6.2.3.0, 6.2.3.1, 2.6.0, 2.6.1, 2.6.2, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0, 6.0, 6.1, 6.2, 3.1.0, 3.2.0, 12.2.2, 12.3.3, 3.4, 4.0, 7.3.3, 8.0.0, 8.0.4, 8.0.5, 8.0.2, 8.0.6, 7.1, 7.2, 9.0.11, 4.2.0, 4.2.1, 18.1, 9.1.0, 5.2, 5.4, 5.5, 9.2, 19.1, 8.55, 8.56, 8.57, 15.2, 16.2, 17.12, 17.1, 16.1, 18.8, 2.3.0, 15.0.2, 15.0, 16.0, 1.60.9, 1.64.0, 18.10, 18.11, 4.3.0.1, 11.1.1.8.0, 12.1.3.0, 12.2.1.3
Timeline
Official Publish:
January 18th, 2018
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.