Jquery · Jquery · CVE-2017-6929
**Name of the Vulnerable Software and Affected Versions**
Drupal versions prior to 8.4.0
Drupal 7 versions prior to 7.57
**Description**
A cross-site scripting issue is present in jQuery when making Ajax requests to untrusted domains. This issue requires contributed or custom modules to be exploitable.
**Recommendations**
For Drupal 8 versions prior to 8.4.0, update to Drupal 8.4.0 or later to resolve the issue.
For Drupal 7 versions prior to 7.57, update to Drupal 7.57 or later to resolve the issue.