CVE-2017-6929

MEDIUM

Drupal 7.0-7.56 and 8.0-8.3.x - Cross-Site Scripting via jQuery Ajax Requests

Title source: llm
STIX 2.1

Description

A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulnerability was already fixed in Drupal 8.4.0 in the Drupal core upgrade to jQuery 3. For Drupal 7, it is fixed in the current release (Drupal 7.57) for jQuery 1.4.4 (the version that ships with Drupal 7 core) as well as for other newer versions of jQuery that might be used on the site, for example using the jQuery Update module.

References (3)

Core 3
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4123
Issue Tracking mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/02/msg00030.html
Mitigation, Vendor Advisory x_refsource_confirm
https://www.drupal.org/sa-core-2018-001

Scores

CVSS v3 6.1
EPSS 0.0060
EPSS Percentile 69.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (6)
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
drupal/core 7.0 - 7.57Packagist
drupal/drupal 7.0 - 7.57
drupal/drupal 8.0 - 8.4.0Packagist
Published Mar 01, 2018
Tracked Since Feb 18, 2026