VDB
BDU%3A2023-07675
BDU%3A2023-07675
PUBLISHED
CVSS 6.400000095367432 MEDIUM
Уязвимость библиотеки jQuery, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить межсайтовй скриптинг
Risk Scores
CVSS 2.0
6.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., Novell Inc., The jQuery Foundation, NetApp Inc., AVEVA Software, LLC, Red Hat Inc., dotCMS LLC, Сообщество свободного программного обеспечения, Ruby Team | Enterprise Manager Ops Center, Fusion Middleware MapViewer, Business Process Management Suite, JD Edwards EnterpriseOne Tools, Primavera Unifier, Hospitality Reporting and Analytics, WebCenter Sites, Oracle JDeveloper, Communications Converged Application Server, Communications WebRTC Session Controller, OpenSUSE Leap, Oracle Hospitality Guest Access, Primavera Gateway, Oracle Hospitality Materials Control, Oracle Service Bus, Oracle Healthcare Translational Research, Oracle Retail Customer Insights, Financial Services Analytical Applications Infrastructure, Financial Services Funds Transfer Pricing, Oracle Endeca Information Discovery Studio, Banking Platform, Oracle Retail Invoice Matching, Oracle Hospitality Cruise Fleet Management, jQuery, NetApp SolidFire & HCI Storage Node, InTouch Access Anywhere, Red Hat Data Grid, Red Hat JBoss A-MQ, Red Hat JBoss Fuse, dotCMS, RetireJS, Ruby, Agile Product Lifecycle Management for Process, Communications Interactive Session Recorder, Communications Services Gatekeeper, Enterprise Operations Monitor, Financial Services Data Integration Hub, Financial Services Asset Lliability Management, Financial Services Hedge Management and Ifrs valuations, Financial Services Liquidity Risk Management, Financial Services Loan Loss Forecasting and Provisioning, Financial Services Market Risk Measurement and Management, Financial Services Profitability Management, Financial Services Reconciliation Framework, Oracle Healthcare Foundation, Insurance Insbridge Rating and Underwriting, OSS Support Tools, Oracle PeopleSoft Enterprise PeopleTools, Oracle Real-Time Scheduler, Retail Allocation, Oracle Retail Sales Audit, Retail Workforce Management Software, Siebel UI Framework, Oracle Utilities Framework, Oracle Utilities Mobile Workforce Management |
Timeline
- Nov 11, 2023 CVE Published
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html url
- http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html url
- http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html url
- http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html url
- http://seclists.org/fulldisclosure/2019/May/10 url
- http://seclists.org/fulldisclosure/2019/May/11 url
- http://seclists.org/fulldisclosure/2019/May/13 url
- http://www.securityfocus.com/bid/105658 url
- https://access.redhat.com/errata/RHSA-2020:0729 url
- https://github.com/jquery/jquery/commit/f60729f3903d17917dc351f3ac87794de379b0cc url
- https://github.com/jquery/jquery/issues/2432 url
- https://github.com/jquery/jquery/pull/2588 url
- https://github.com/jquery/jquery/pull/2588/commits/c254d308a7d3f1eac4d0b42837804cfffcba4bb2 url
- https://ics-cert.us-cert.gov/advisories/ICSA-18-212-04 url
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601 url
- https://lists.apache.org/thread.html/10f0f3aefd51444d1198c65f44ffdf2d78ca3359423dbc1c168c9731%40%3Cdev.flink.apache.org%3E url
- https://lists.apache.org/thread.html/17ff53f7999e74fbe3cc0ceb4e1c3b00b180b7c5afec8e978837bc49%40%3Cuser.flink.apache.org%3E url
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E url
- https://lists.apache.org/thread.html/52bafac05ad174000ea465fe275fd3cc7bd5c25535a7631c0bc9bfb2%40%3Cuser.flink.apache.org%3E url
- https://lists.apache.org/thread.html/54df3aeb4239b64b50b356f0ca6f986e3c4ca5b84c515dce077c7854%40%3Cuser.flink.apache.org%3E url
…and 22 more