{"id":"GHSA-jmh9-6rjq-gjh9","summary":"Vulnerable embedded jQuery Version","details":"### Summary\nPIMCore uses the JavaScript library jQuery in version 3.4.1. This version is vulnerable to cross-site-scripting (XSS).\n\n### Details\nIn jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.\n\nPublish Date: 2020-04-29\n\nURL:= https://security.snyk.io/package/npm/jquery/3.4.1\n","modified":"2024-12-02T05:44:54.860243Z","published":"2024-06-05T13:28:36Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-06-05T13:28:36Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/pimcore/admin-ui-classic-bundle/security/advisories/GHSA-jmh9-6rjq-gjh9"},{"type":"PACKAGE","url":"https://github.com/pimcore/admin-ui-classic-bundle"}],"affected":[{"package":{"name":"pimcore/admin-ui-classic-bundle","ecosystem":"Packagist","purl":"pkg:composer/pimcore/admin-ui-classic-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.3"}]}],"versions":["1.4.0","v1.0.0","v1.0.0-BETA1","v1.0.0-RC1","v1.0.0-RC2","v1.0.1","v1.0.2","v1.0.3","v1.0.4","v1.0.5","v1.0.6","v1.1.0","v1.1.0-RC1","v1.1.1","v1.1.2","v1.1.3","v1.1.4","v1.2","v1.2.0-RC1","v1.2.1","v1.2.2","v1.2.3","v1.3.0","v1.3.0-RC1","v1.3.1","v1.3.2","v1.3.3","v1.3.4","v1.3.5","v1.4.1","v1.4.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.4.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-jmh9-6rjq-gjh9/GHSA-jmh9-6rjq-gjh9.json"}}],"schema_version":"1.9.0"}