js-jquery: XSS via improper selector detection
Published Jan 18, 2018
6.8
MEDIUMCVSS 3.0
EPSS 8.63%
Description
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '<' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '<' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.
Affected products
No data.
No data.
CloudForms Management Engine 5
cfme-gemset
Not affected
Red Hat 3scale API Management Platform 2
jquery
Fix deferred
Red Hat Enterprise Linux 6
ipa
Not affected
Red Hat Enterprise Linux 6
pcp
Will not fix
Red Hat Enterprise Linux 6
python-coverage
Will not fix
Red Hat Enterprise Linux 6
python-weberror
Will not fix
Red Hat Enterprise Linux 7
ipa
Not affected
Red Hat Enterprise Linux 7
ipsilon
Not affected
Red Hat Enterprise Linux 7
pcp
Will not fix
Red Hat Enterprise Linux 7
pki-core
Not affected
Red Hat Enterprise Linux 7
publican
Affected
Red Hat Enterprise Linux 7
python-coverage
Will not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
python-XStatic-jQuery
Not affected
Red Hat JBoss Fuse Integration Service 2
jquery
Not affected
Red Hat Mobile Application Platform 4
millicore
Not affected
Red Hat OpenStack Platform 10 (Newton)
python-XStatic-jQuery
Not affected
Red Hat OpenStack Platform 11 (Ocata)
python-XStatic-jQuery
Not affected
Red Hat OpenStack Platform 12 (Pike)
python-XStatic-jQuery
Not affected
Red Hat OpenStack Platform 13 (Queens)
python-XStatic-jQuery
Not affected
Red Hat OpenStack Platform 9 (Mitaka)
python-XStatic-jQuery
Not affected
Red Hat Process Automation 7
js-jquery
Out of support scope
Red Hat Satellite 6
ruby193-rubygem-jquery-ui-rails
Will not fix
Red Hat Satellite 6
tfm-rubygem-jquery-ui-rails
Not affected
Red Hat Software Collections
python27-python-coverage
Will not fix
Red Hat Software Collections
python27-python-werkzeug
Will not fix
Red Hat Software Collections
rh-python35-python-coverage
Not affected
Red Hat Software Collections
rh-python36-python-coverage
Not affected
Red Hat Software Collections
rh-ror42-rubygem-jquery-rails
Not affected
Red Hat Software Collections
rh-ror42-rubygem-simplecov-html
Will not fix
Red Hat Software Collections
rh-ror50-rubygem-jquery-rails
Not affected
Red Hat Subscription Asset Manager
katello-headpin
Will not fix
Red Hat Subscription Asset Manager
ruby193-rubygem-apipie-rails
Will not fix
Red Hat Subscription Asset Manager
ruby193-rubygem-jquery-rails
Will not fix
Red Hat Subscription Asset Manager
ruby193-rubygemrui_alchemy-rails
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | cfme-gemset | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | jquery | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | ipa | Not affected | n/a |
| Red Hat Enterprise Linux 6 | pcp | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | python-coverage | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | python-weberror | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | ipa | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ipsilon | Not affected | n/a |
| Red Hat Enterprise Linux 7 | pcp | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | pki-core | Not affected | n/a |
| Red Hat Enterprise Linux 7 | publican | Affected | n/a |
| Red Hat Enterprise Linux 7 | python-coverage | Will not fix | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat JBoss Fuse Integration Service 2 | jquery | Not affected | n/a |
| Red Hat Mobile Application Platform 4 | millicore | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat OpenStack Platform 12 (Pike) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat Process Automation 7 | js-jquery | Out of support scope | n/a |
| Red Hat Satellite 6 | ruby193-rubygem-jquery-ui-rails | Will not fix | n/a |
| Red Hat Satellite 6 | tfm-rubygem-jquery-ui-rails | Not affected | n/a |
| Red Hat Software Collections | python27-python-coverage | Will not fix | n/a |
| Red Hat Software Collections | python27-python-werkzeug | Will not fix | n/a |
| Red Hat Software Collections | rh-python35-python-coverage | Not affected | n/a |
| Red Hat Software Collections | rh-python36-python-coverage | Not affected | n/a |
| Red Hat Software Collections | rh-ror42-rubygem-jquery-rails | Not affected | n/a |
| Red Hat Software Collections | rh-ror42-rubygem-simplecov-html | Will not fix | n/a |
| Red Hat Software Collections | rh-ror50-rubygem-jquery-rails | Not affected | n/a |
| Red Hat Subscription Asset Manager | katello-headpin | Will not fix | n/a |
| Red Hat Subscription Asset Manager | ruby193-rubygem-apipie-rails | Will not fix | n/a |
| Red Hat Subscription Asset Manager | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat Subscription Asset Manager | ruby193-rubygemrui_alchemy-rails | Will not fix | n/a |
jquery
npm
Introduced 0 Fixed 1.9.0org.webjars.npm:jquery
Maven
Introduced 0 Fixed 1.9.0jQuery
NuGet
Introduced 0 Fixed 1.9.0jquery-rails
RubyGems
Introduced 0 Fixed 2.2.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | jquery | 0 | 1.9.0 |
| Maven | org.webjars.npm:jquery | 0 | 1.9.0 |
| NuGet | jQuery | 0 | 1.9.0 |
| RubyGems | jquery-rails | 0 | 2.2.0 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (24 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.63% (0.08632) | 94.95th | v5 (v2026.06.15) |
| Sep 22, 2026 | 8.63% (0.08632) | 94.86th | v5 (v2026.06.15) |
| Sep 21, 2026 | 11.50% (0.11504) | 95.88th | v5 (v2026.06.15) |
| Sep 6, 2026 | 8.63% (0.08632) | 94.74th | v5 (v2026.06.15) |
| Sep 5, 2026 | 11.50% (0.11504) | 95.79th | v5 (v2026.06.15) |
| Aug 30, 2026 | 8.63% (0.08632) | 94.71th | v5 (v2026.06.15) |
| Aug 28, 2026 | 11.50% (0.11504) | 95.77th | v5 (v2026.06.15) |
| Aug 24, 2026 | 8.63% (0.08632) | 94.68th | v5 (v2026.06.15) |
| Aug 23, 2026 | 11.50% (0.11504) | 95.76th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.79% (0.08793) | 94.49th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.35% (0.01354) | 78.34th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.73% (0.02728) | 76.55th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.16% (0.01164) | 77.14th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.82% (0.00823) | 82.60th | v3 (v2023.03.01) |
| May 3, 2024 | 0.82% (0.00823) | 81.80th | v3 (v2023.03.01) |
| Aug 14, 2023 | 0.82% (0.00823) | 79.73th | v3 (v2023.03.01) |
| Jun 11, 2023 | 1.16% (0.01164) | 82.93th | v3 (v2023.03.01) |
| May 8, 2023 | 1.67% (0.01670) | 85.74th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.44% (0.01441) | 84.53th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.83% (0.04829) | 89.27th | v2 (v2022.01.01) |
| Nov 15, 2022 | 4.83% (0.04829) | 88.89th | v2 (v2022.01.01) |
| Jul 15, 2022 | 1.54% (0.01537) | 73.27th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.83% (0.04829) | 88.20th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.83% (0.04829) | 74.65th | v2 (v2022.01.01) |
References (29)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html vendor-advisoryx_refsource_SUSE
- http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html x_refsource_MISC
- http://packetstormsecurity.com/files/161972/Linksys-EA7500-2.0.8.194281-Cross-Site-Scripting.html x_refsource_MISC
- http://www.securityfocus.com/bid/102792 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2012-6708 Vendor Advisory
- https://bugs.jquery.com/ticket/11290 x_refsource_MISCExploitIssue TrackingVendor Advisory
- https://bugs.jquery.com/ticket/12531
- https://bugs.jquery.com/ticket/6429
- https://bugs.jquery.com/ticket/9521
- https://bugzilla.redhat.com/show_bug.cgi?id=1591840 Issue Tracking
- https://github.com/advisories/GHSA-2pqj-h3vj-pqgw Advisory
- https://github.com/jquery/jquery/commit/05531fc4080ae24070930d15ae0cea7ae056457d x_refsource_MISCPatchThird Party Advisory
- https://github.com/rails/jquery-rails/blob/v2.1.4/vendor/assets/javascripts/jquery.js#L59
- https://github.com/rails/jquery-rails/blob/v2.2.0/vendor/assets/javascripts/jquery.js#L67
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2012-6708.yml
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 x_refsource_CONFIRMThird Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2012-6708
- https://nvd.nist.gov/vuln/detail/CVE-2017-16011
- https://research.insecurelabs.org/jquery/test/
- https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450223
- https://snyk.io/vuln/npm:jquery:20120206 x_refsource_MISCPatchThird Party Advisory
- https://web.archive.org/web/20200227132049/http://www.securityfocus.com/bid/102792
- https://www.cve.org/CVERecord?id=CVE-2012-6708
Change history (0)
No recorded changes yet.