-
Notifications
You must be signed in to change notification settings - Fork 1
Description
Vulnerable Package issue exists @ Npm-jquery-1.4.2 in branch qa
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Namespace: ksalman-Cx-org-NA-kelsey-na
Repository: Webgoat.NET-base
Repository Url: https://github.com/ksalman-Cx-org-NA-kelsey-na/Webgoat.NET-base
CxAST-Project: ksalman-Cx-org-NA-kelsey-na/Webgoat.NET-base
CxAST platform scan: 5408ca2a-613e-4804-9971-3fbb7d15f128
Branch: qa
Application: Webgoat.NET-base
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-79
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: 3.5.0
References
Advisory
Release Note
Pull request
Commit