gpt4 book ai didi

jquery - jQuery 1.x 是否容易受到 "non-explicit data type cross-site scripting"的攻击?

转载 作者:行者123 更新时间:2023-12-01 02:18:25 24 4
gpt4 key购买 nike

我们最近收到了来自 https://nospam_srcclr.com 的以下电子邮件(删除真实网址的 nospam_)。

Thank you for your prompt reply. We have identified [our project] as being vulnerable to a cross-site scripting vulnerability through JQuery.

https://nospam_srcclr.com/security/cross-site-scripting-xss-through-execution-non-explicit-data-type/javascript/sid-2250/fix

A copy of the JQuery version 1.11.3 is included in the project here. JQuery is vulnerable to cross-site scripting through execution of non-explicit data type. The vulnerable section of code used in [our project] is seen here.

To mitigate this issue, we recommend upgrading JQuery to 3.0.0.

jQuery 1.x 使用起来真的不安全吗?

最佳答案

如果您没有通过ajax从另一个不受信任的域获取任何javascript,它仍然是安全的。

如果你这样做了,您可以手动将这个简单的补丁应用到当前的 jquery:

https://github.com/jquery/jquery/commit/b078a62013782c7424a4a61a240c23c4c0b42614

关于jquery - jQuery 1.x 是否容易受到 "non-explicit data type cross-site scripting"的攻击?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/38115114/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com