Revision Date: | 2018-01-18 | Version: | 1 | Title: | CVE-2012-6708 on Ubuntu 18.04 LTS (bionic) - low. | Description: | jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '<' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '<' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2012-6708
| Platform(s): | Ubuntu 18.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 18.04 LTS (bionic) is installed. AND NOT libjs-jquery package in bionic, while related to the CVE in some way, is not affected.
|
|