[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252588

 
 

909

 
 

196930

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1519 --- ipa

ID: oval:org.secpod.oval:def:1700459Date: (C)2020-11-05   (M)2024-05-22
Class: PATCHFamily: unix




jQuery before 3.0.0 is vulnerable to Cross-site Scripting attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041 . In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute. In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property. A Prototype Pollution vulnerability was found in jquery. Untrusted JSON passed to the `extend` function could lead to modifying objects up the prototype chain, including the global Object. A crafted JSON object passed to a vulnerable method could lead to denial of service or data injection, with various consequences. A cross-site scripting vulnerability was discovered in bootstrap. If an attacker could control the data given to tooltip or popover, they could inject HTML or Javascript into the rendered page when tooltip or popover events fired. A Cross-site scripting vulnerability exists in JQuery. This flaw allows an attacker with the ability to supply input to the "HTML" function to inject Javascript into the page where that input is rendered, and have it delivered by the browser. A flaw was found in IPA. When sending a very long password

Platform:
Amazon Linux 2
Product:
ipa
Reference:
ALAS2-2020-1519
CVE-2015-9251
CVE-2016-10735
CVE-2018-14040
CVE-2018-14042
CVE-2018-20676
CVE-2018-20677
CVE-2019-11358
CVE-2019-8331
CVE-2020-11022
CVE-2020-1722
CVE    10
CVE-2019-8331
CVE-2020-1722
CVE-2018-14040
CVE-2020-11022
...

© SecPod Technologies