Candidate: CVE-2015-9251 PublicDate: 2018-01-18 23:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9251 https://github.com/jquery/jquery/pull/2588 https://snyk.io/vuln/npm:jquery:20150627 https://github.com/jquery/jquery/pull/2588/commits/c254d308a7d3f1eac4d0b42837804cfffcba4bb2 Description: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. Ubuntu-Description: Notes: mdeslaur> fix is intrusive and backwards-incompatible, see bug 3011 mdeslaur> Due to this, we will not be fixing this issue in Ubuntu stable mdeslaur> releases. Marking as ignored. Bugs: https://github.com/jquery/jquery/issues/2432 https://github.com/jquery/jquery/issues/3011 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_jquery: upstream: https://github.com/jquery/jquery/commit/f60729f3903d17917dc351f3ac87794de379b0cc upstream_jquery: released (3.1.1-1) precise/esm_jquery: ignored trusty_jquery: ignored (reached end-of-life) trusty/esm_jquery: ignored xenial_jquery: ignored esm-infra/xenial_jquery: ignored artful_jquery: not-affected (3.1.1-2) bionic_jquery: not-affected cosmic_jquery: not-affected disco_jquery: not-affected eoan_jquery: not-affected focal_jquery: not-affected devel_jquery: not-affected