Skip to content

jQuery Cross Site Scripting vulnerability

Moderate severity GitHub Reviewed Published Jun 26, 2023 to the GitHub Advisory Database • Updated Apr 1, 2024

Package

nuget jQuery (NuGet)

Affected versions

>= 1.0.3, < 3.5.0

Patched versions

3.5.0
npm jquery (npm)
>= 1.0.3, < 3.5.0
3.5.0
bundler jquery-rails (RubyGems)
< 4.4.0
4.4.0
maven org.webjars.npm:jquery (Maven)
>= 1.0.3, < 3.5.0
3.5.0
Published by the National Vulnerability Database Jun 26, 2023
Published to the GitHub Advisory Database Jun 26, 2023
Reviewed Jul 7, 2023
Last updated Apr 1, 2024

Severity

Moderate
6.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CVE ID

CVE-2020-23064

GHSA ID

GHSA-257q-pv89-v3xv

Source code

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.