{"id":"GHSA-hgwm-pv9h-q5m7","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hgwm-pv9h-q5m7","summary":"Potential XSS in jQuery dependency in Mirador","details":"### Impact\nMirador users less than v3.0.0 (alpha-rc) versions that have an unpatched jQuery. When adopters update jQuery they will find some of Mirador functionality to be broken.\n\n### Patches\nMirador adopters should update to v3.0.0, no updates exist for v2.x releases.\n\n### Workarounds\nYes, Mirador users could fork and create their own custom build of Mirador and make the bug fixes themselves.\n\n### References\nhttps://github.com/advisories/GHSA-gxr4-xjj5-5px2\nhttps://github.com/advisories/GHSA-jpcq-cgw6-v4j6\n\n\nhttps://blog.jquery.com/2020/04/10/jquery-3-5-0-released/\nhttps://jquery.com/upgrade-guide/3.5/","published":"2020-09-18T18:03:29Z","modified":"2021-10-04T21:19:55Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mirador","fixedVersion":"3.0.0-alpha.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ProjectMirador/mirador/security/advisories/GHSA-hgwm-pv9h-q5m7"},{"type":"PACKAGE","url":"https://github.com/ProjectMirador/mirador"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-10-04T21:19:55Z"}}