USN-7246-1: jQuery vulnerabilities
Published Jan 30, 2025
·Updated
It was discovered that jQuery incorrectly handled parsing untrusted HTML. A remote attacker could possibly use this issue to execute arbitrary code.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/libjs-jquery<3.3.1~dfsg-3ubuntu0.1
3.3.1~dfsg-3ubuntu0.1
Ubuntu Ubuntu=20.04
Event History
Jan 30, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7246-1?
The severity of USN-7246-1 is considered high due to the potential for remote code execution.
2
How do I fix USN-7246-1?
To fix USN-7246-1, update the libjs-jquery package to version 3.3.1~dfsg-3ubuntu0.1 or later.
3
Which systems are affected by USN-7246-1?
USN-7246-1 affects Ubuntu 20.04 systems that use the libjs-jquery package.
4
What attack vectors are associated with USN-7246-1?
USN-7246-1 can be exploited by a remote attacker through the execution of arbitrary code via untrusted HTML.
5
Is there a workaround for USN-7246-1?
There is no official workaround for USN-7246-1; updating to the patched version is the recommended action.