CVE-2022-23395: XSS
Published Mar 2, 2022
·Updated
jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).
Affected Software
1 affected component
Jquery.cookie Project Jquery.cookie Node.js=1.4.1
Event History
Mar 2, 2022
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-23395.
2
What is the severity of CVE-2022-23395?
The severity of CVE-2022-23395 is medium (6.1).
3
Which software versions are affected by CVE-2022-23395?
jQuery Cookie 1.4.1 is affected by CVE-2022-23395.
4
What is the impact of CVE-2022-23395?
CVE-2022-23395 can lead to DOM cross-site scripting (XSS) due to prototype pollution.
5
How can I fix CVE-2022-23395?
To fix CVE-2022-23395, update to a version of jQuery Cookie that is not affected by the vulnerability.