GHSA-hgwm-pv9h-q5m7

Suggest an improvement
Source
https://github.com/advisories/GHSA-hgwm-pv9h-q5m7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hgwm-pv9h-q5m7/GHSA-hgwm-pv9h-q5m7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hgwm-pv9h-q5m7
Published
2020-09-18T18:03:29Z
Modified
2021-10-04T21:19:55Z
Summary
Potential XSS in jQuery dependency in Mirador
Details

Impact

Mirador users less than v3.0.0 (alpha-rc) versions that have an unpatched jQuery. When adopters update jQuery they will find some of Mirador functionality to be broken.

Patches

Mirador adopters should update to v3.0.0, no updates exist for v2.x releases.

Workarounds

Yes, Mirador users could fork and create their own custom build of Mirador and make the bug fixes themselves.

References

https://github.com/advisories/GHSA-gxr4-xjj5-5px2 https://github.com/advisories/GHSA-jpcq-cgw6-v4j6

https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://jquery.com/upgrade-guide/3.5/

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-09-17T21:56:19Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / mirador

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.0-alpha.0

Database specific

last_known_affected_version_range
"<= 2.7.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hgwm-pv9h-q5m7/GHSA-hgwm-pv9h-q5m7.json"