<?xml version="1.0" encoding="UTF-8"?>
<VrdaData xsi:schemaLocation="http://vrda.jpcert.or.jp/feed/xsd/vrda_data.xsd" xmlns="http://vrda.jpcert.or.jp" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" refvuldefversion="1.2">
  <VrdaDataProvider>
    <Name>JVN iPedia</Name>
    <URL>http://jvndb.jvn.jp</URL>
  </VrdaDataProvider>
  <VrdaDataSourceType>Advisory</VrdaDataSourceType>
  <Vulinfo lang="en" invalidated="false" revisionno="1">
    <VulinfoID>JVNDB-2015-008097</VulinfoID>
    <VulinfoData>
      <Title>jQuery &#12395;&#12362;&#12369;&#12427;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;</Title>
      <VulinfoDescription>
        <Overview>jQuery &#12395;&#12399;&#12289;&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;&#12398;&#33030;&#24369;&#24615;&#12364;&#23384;&#22312;&#12375;&#12414;&#12377;&#12290;</Overview>
      </VulinfoDescription>
      <Affected>
        <AffectedItem affectedstatus="vulnerable">
          <Lapt>cpe:/a:jquery:jquery</Lapt>
        </AffectedItem>
      </Affected>
      <FactAnalysis>
        <AccessComplexity>Medium</AccessComplexity>
        <AccessVector>Network</AccessVector>
        <Authentication>None</Authentication>
        <AvailabilityImpact>None</AvailabilityImpact>
        <ConfidentialityImpact>None</ConfidentialityImpact>
        <IntegrityImpact>Partial</IntegrityImpact>
      </FactAnalysis>
      <Related>
        <RelatedItem origin="jvnipedia" relationtype="self">
          <URL>http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-008097.html</URL>
        </RelatedItem>
        <RelatedItem origin="other" relationtype="alternate">
          <Name>Common Vulnerabilities and Exposures (CVE)</Name>
          <VulinfoID>CVE-2015-9251</VulinfoID>
          <URL>https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9251</URL>
        </RelatedItem>
        <RelatedItem origin="other" relationtype="alternate">
          <Name>National Vulnerability Database (NVD)</Name>
          <VulinfoID>CVE-2015-9251</VulinfoID>
          <URL>https://nvd.nist.gov/vuln/detail/CVE-2015-9251</URL>
        </RelatedItem>
        <RelatedItem origin="other" relationtype="reference">
          <Name>GitHub</Name>
          <VulinfoID>Inadequate/dangerous jQuery behavior for 3rd party text/javascript responses #2432</VulinfoID>
          <URL>https://github.com/jquery/jquery/issues/2432</URL>
        </RelatedItem>
        <RelatedItem origin="other" relationtype="reference">
          <Name>GitHub</Name>
          <VulinfoID>Ajax: Mitigate possible XSS vulnerability #2588 (c254d30)</VulinfoID>
          <URL>https://github.com/jquery/jquery/pull/2588/commits/c254d308a7d3f1eac4d0b42837804cfffcba4bb2</URL>
        </RelatedItem>
        <RelatedItem origin="other" relationtype="reference">
          <Name>GitHub</Name>
          <VulinfoID>Ajax: Mitigate possible XSS vulnerability #2588</VulinfoID>
          <URL>https://github.com/jquery/jquery/pull/2588</URL>
        </RelatedItem>
        <RelatedItem origin="other" relationtype="reference">
          <Name>GitHub</Name>
          <VulinfoID>Ajax: Mitigate possible XSS vulnerability</VulinfoID>
          <URL>https://github.com/jquery/jquery/commit/f60729f3903d17917dc351f3ac87794de379b0cc</URL>
        </RelatedItem>
        <RelatedItem origin="other" relationtype="reference">
          <Name>&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;</Name>
          <VulinfoID>CWE-79</VulinfoID>
          <URL>http://jvndb.jvn.jp/ja/cwe/CWE-79.html</URL>
        </RelatedItem>
        <RelatedItem origin="other" relationtype="reference">
          <Name>&#20849;&#36890;&#33030;&#24369;&#24615;&#12479;&#12452;&#12503;&#19968;&#35239; (CWE)</Name>
          <VulinfoID>&#12463;&#12525;&#12473;&#12469;&#12452;&#12488;&#12473;&#12463;&#12522;&#12503;&#12486;&#12451;&#12531;&#12464;(CWE-79)</VulinfoID>
          <URL>http://jvndb.jvn.jp/ja/cwe/CWE-79.html</URL>
        </RelatedItem>
      </Related>
      <DateFirstPublished>2018-02-16T16:46:00+09:00</DateFirstPublished>
      <DateLastUpdated>2018-02-16T16:46:00+09:00</DateLastUpdated>
    </VulinfoData>
  </Vulinfo>
</VrdaData>
