CVE-2015-9251

Related Vulnerabilities: CVE-2015-9251  

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

The MITRE CVE dictionary describes this issue as:

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Find out more about CVE-2015-9251 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 6.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Impact Low
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 ruby193-rubygem-jquery-rails Will not fix
Red Hat Software Collections for Red Hat Enterprise Linux rh-ror50-rubygem-jquery-rails Will not fix
Red Hat Software Collections for Red Hat Enterprise Linux rh-ror41-rubygem-jquery-rails Will not fix
Red Hat Software Collections for Red Hat Enterprise Linux rh-ror42-rubygem-jquery-rails Will not fix
Red Hat Satellite 6 ruby193-rubygem-jquery-ui-rails Will not fix
Red Hat Satellite 6 tfm-rubygem-jquery-ui-rails Will not fix
Red Hat OpenStack Platform 9.0 python-XStatic-jQuery Will not fix
Red Hat OpenStack Platform 8.0 (Liberty) python-XStatic-jQuery Will not fix
Red Hat OpenStack Platform 11.0 (Ocata) python-XStatic-jQuery Will not fix
Red Hat OpenStack Platform 10 python-XStatic-jQuery Will not fix
Red Hat OpenShift Enterprise 2 ruby193-rubygem-jquery-rails Will not fix
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 python-XStatic-jQuery Will not fix
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 python-XStatic-jQuery Will not fix
OpenStack 6 Installer for RHEL 7 ruby193-rubygem-jquery-ui-rails Will not fix