<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007pMcJeCAKOkta Classic EngineOkta Integration NetworkAnswered2024-01-19T11:02:07.000Z2022-07-24T03:52:21.000Z2022-07-25T15:56:39.000Z

LarryD.25867 (Customer) asked a question.

Vulnerability on JQuery Okta Sign-In Widget

We observed a vulnerable JavaScript library.

JQuery version 1.12.4, which has the following vulnerabilities:

• CVE-2015-9251: 3rd party CORS request may execute

• CVE-2015-9251: parseHTML() executes scripts in event handlers

• CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution

• CVE-2020-11022: Regex in its jQuery.htmlPrefilter sometimes may introduce XSS

• CVE-2020-11023: Regex in its jQuery.htmlPrefilter sometimes may introduce XSS


This question is closed.
Loading
Vulnerability on JQuery Okta Sign-In Widget