{"id":"GHSA-hgwm-pv9h-q5m7","summary":"Potential XSS in jQuery dependency in Mirador","details":"### Impact\nMirador users less than v3.0.0 (alpha-rc) versions that have an unpatched jQuery. When adopters update jQuery they will find some of Mirador functionality to be broken.\n\n### Patches\nMirador adopters should update to v3.0.0, no updates exist for v2.x releases.\n\n### Workarounds\nYes, Mirador users could fork and create their own custom build of Mirador and make the bug fixes themselves.\n\n### References\nhttps://github.com/advisories/GHSA-gxr4-xjj5-5px2\nhttps://github.com/advisories/GHSA-jpcq-cgw6-v4j6\n\n\nhttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/\nhttps://jquery.com/upgrade-guide/3.5/","modified":"2021-10-04T21:19:55Z","published":"2020-09-18T18:03:29Z","database_specific":{"github_reviewed_at":"2020-09-17T21:56:19Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ProjectMirador/mirador/security/advisories/GHSA-hgwm-pv9h-q5m7"},{"type":"PACKAGE","url":"https://github.com/ProjectMirador/mirador"}],"affected":[{"package":{"name":"mirador","ecosystem":"npm","purl":"pkg:npm/mirador"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.0-alpha.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.7.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hgwm-pv9h-q5m7/GHSA-hgwm-pv9h-q5m7.json"}}],"schema_version":"1.9.0"}