vulnerability

CentOS Linux: CVE-2015-9251: Moderate: ipa security, bug fix, and enhancement update (Multiple Advisories)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
01/18/2018
Added
10/01/2020
Modified
05/25/2023

Description

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

Solution(s)

centos-upgrade-apache-commons-collectionscentos-upgrade-apache-commons-langcentos-upgrade-apache-commons-netcentos-upgrade-bea-stax-apicentos-upgrade-bind-dyndb-ldapcentos-upgrade-bind-dyndb-ldap-debuginfocentos-upgrade-bind-dyndb-ldap-debugsourcecentos-upgrade-custodiacentos-upgrade-glassfish-fastinfosetcentos-upgrade-glassfish-jaxb-apicentos-upgrade-glassfish-jaxb-corecentos-upgrade-glassfish-jaxb-runtimecentos-upgrade-glassfish-jaxb-txw2centos-upgrade-ipa-clientcentos-upgrade-ipa-client-commoncentos-upgrade-ipa-client-debuginfocentos-upgrade-ipa-client-epncentos-upgrade-ipa-client-sambacentos-upgrade-ipa-commoncentos-upgrade-ipa-debuginfocentos-upgrade-ipa-debugsourcecentos-upgrade-ipa-healthcheckcentos-upgrade-ipa-healthcheck-corecentos-upgrade-ipa-python-compatcentos-upgrade-ipa-selinuxcentos-upgrade-ipa-servercentos-upgrade-ipa-server-commoncentos-upgrade-ipa-server-debuginfocentos-upgrade-ipa-server-dnscentos-upgrade-ipa-server-trust-adcentos-upgrade-ipa-server-trust-ad-debuginfocentos-upgrade-jackson-annotationscentos-upgrade-jackson-corecentos-upgrade-jackson-databindcentos-upgrade-jackson-jaxrs-json-providercentos-upgrade-jackson-jaxrs-providerscentos-upgrade-jackson-module-jaxb-annotationscentos-upgrade-jakarta-commons-httpclientcentos-upgrade-javassistcentos-upgrade-javassist-javadoccentos-upgrade-jsscentos-upgrade-jss-debuginfocentos-upgrade-jss-debugsourcecentos-upgrade-jss-javadoccentos-upgrade-ldapjdkcentos-upgrade-ldapjdk-javadoccentos-upgrade-opendnsseccentos-upgrade-opendnssec-debuginfocentos-upgrade-opendnssec-debugsourcecentos-upgrade-pki-basecentos-upgrade-pki-base-javacentos-upgrade-pki-cacentos-upgrade-pki-core-debuginfocentos-upgrade-pki-core-debugsourcecentos-upgrade-pki-kracentos-upgrade-pki-servercentos-upgrade-pki-servlet-4-0-apicentos-upgrade-pki-servlet-enginecentos-upgrade-pki-symkeycentos-upgrade-pki-symkey-debuginfocentos-upgrade-pki-toolscentos-upgrade-pki-tools-debuginfocentos-upgrade-python-nss-debugsourcecentos-upgrade-python-nss-doccentos-upgrade-python2-ipaclientcentos-upgrade-python2-ipalibcentos-upgrade-python2-ipaservercentos-upgrade-python3-custodiacentos-upgrade-python3-ipaclientcentos-upgrade-python3-ipalibcentos-upgrade-python3-ipaservercentos-upgrade-python3-jwcryptocentos-upgrade-python3-kdcproxycentos-upgrade-python3-nsscentos-upgrade-python3-nss-debuginfocentos-upgrade-python3-pkicentos-upgrade-python3-pyusbcentos-upgrade-python3-qrcodecentos-upgrade-python3-qrcode-corecentos-upgrade-python3-yubicocentos-upgrade-relaxngdatatypecentos-upgrade-resteasycentos-upgrade-slapi-niscentos-upgrade-slapi-nis-debuginfocentos-upgrade-slapi-nis-debugsourcecentos-upgrade-slf4jcentos-upgrade-slf4j-jdk14centos-upgrade-softhsmcentos-upgrade-softhsm-debuginfocentos-upgrade-softhsm-debugsourcecentos-upgrade-softhsm-develcentos-upgrade-stax-excentos-upgrade-tomcatjsscentos-upgrade-velocitycentos-upgrade-xalan-j2centos-upgrade-xerces-j2centos-upgrade-xml-commons-apiscentos-upgrade-xml-commons-resolvercentos-upgrade-xmlstreambuffercentos-upgrade-xsom
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.