{"id":2118,"date":"2020-05-28T16:44:39","date_gmt":"2020-05-28T21:44:39","guid":{"rendered":"https:\/\/cert.pa\/?p=2118"},"modified":"2020-06-08T19:50:19","modified_gmt":"2020-06-09T00:50:19","slug":"csirt-panama-aviso-2020-05-27-jquery-actualizaciones-de-multiples-vulnerabilidades-que-afectan-a-su-biblioteca-multiplataforma-javascript","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=2118","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2020-05-27 jQuery: Actualizaciones de M\u00faltiples vulnerabilidades que afectan a su biblioteca multiplataforma JavaScript."},"content":{"rendered":"\n<p>Gravedad:Media                                                                                                              Vulnerabilidad: CVE-2020-7656                                                                       <\/p>\n\n\n\n<p>Fecha de publicaci\u00f3n: Mayo 27, 2020<br> \u00daltima revisi\u00f3n: Mayo 27, 2020<br> Portal: https:\/\/jquery.com\/<\/p>\n\n\n\n<p><strong>Sistemas Afectados:<\/strong><br>\nVulnerabilidades de seguridad que afectan a todas las versiones de jQuery desde\nla versi\u00f3n 1.0 hasta la 1.8.3.<\/p>\n\n\n\n<p><strong>I. Descripci\u00f3n<\/strong><br> Actualizaci\u00f3n de seguridad que afecta a la biblioteca multiplataforma JavaScript. <\/p>\n\n\n\n<p><strong>II. Impacto<\/strong><\/p>\n\n\n\n<p>Vulnerabilidad: CVE-2020-7656<\/p>\n\n\n\n<p>Debido a que la funci\u00f3n\n\u201cload()\u201d falla al reconocer y remover las marcas HTML &lt;script&gt; que\ncontengan un espacio en blanco, por ejemplo, \u201c&lt;\/script &gt;\u201d, esto\npermitir\u00eda a un atacante remoto realizar ataques XSS (Cross-site Scripting)\npara el robo de informaci\u00f3n sensible, enga\u00f1ar usuarios, cambiar la apariencia\ndel sitio, entre otros m\u00e9todos.<\/p>\n\n\n\n<p>Actualmente se cuenta con informaci\u00f3n p\u00fablica para explotar esta vulnerabilidad, por lo que se recomienda actualizar a la brevedad.<\/p>\n\n\n\n<p><strong>III. Referencia a soluciones, herramientas e\ninformaci\u00f3n<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Actualizar a las versiones de jQuery 1.9.0 o superior, mediante su sitio web (https:\/\/jquery.com\/download\/). <\/p>\n\n\n\n<p><strong>Fuentes:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Develop fast Stay secure. SNYK. Cross-site Scripting (XSS). Recopilado en: \u00a0<a href=\"https:\/\/snyk.io\/vuln\/SNYK-JS-JQUERY-569619\">https:\/\/snyk.io\/vuln\/SNYK-JS-JQUERY-569619<\/a><\/li><li>Common Vulnerabilities and Exposures (CVE). Recopilado en: \u00a0https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-7656<\/li><li>CSIRT Chile. 26 de mayo del 2020. Vulnerabilidades. Recopilado en: https:\/\/www.csirt.gob.cl\/vulnerabilidades\/9vsa20-00225-01\/<br><br><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Gravedad:Media Vulnerabilidad: CVE-2020-7656 Fecha de publicaci\u00f3n: Mayo 27, 2020 \u00daltima revisi\u00f3n: Mayo 27, 2020 Portal: https:\/\/jquery.com\/ Sistemas Afectados: Vulnerabilidades de seguridad que afectan a todas las versiones de jQuery desde la versi\u00f3n 1.0 hasta la&#8230;<\/p>\n","protected":false},"author":4,"featured_media":2119,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-2118","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2118"}],"version-history":[{"count":8,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2118\/revisions"}],"predecessor-version":[{"id":2127,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2118\/revisions\/2127"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/2119"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}