GHSA-5vpr-v24w-mmjj · Severity: medium · Ecosystem: composer — Drupal cross site scripting vulnerability
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulnerability was already fixed in Drupal 8.4.0 in the Drupal core upgrade to jQuery 3. For Drupal 7, it is fixed in the current release (Drupal 7.57) for jQuery 1.4.4 (the version that ships with Drupal 7 core) as well as for other newer versions of jQuery that might be used on the site, for example using the jQuery Update module.
Conclusion & alert: CVE-2017-6929 is rated Moderate Risk (48.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.27%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.60% | 1.27% | +0.66% |
| 2 | 2025-12-28 | 0.53% | 0.60% | +0.07% |
| 3 | 2025-12-27 | — | 0.53% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 3.0 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-5vpr-v24w-mmjj · Severity: medium · Ecosystem: composer — Drupal cross site scripting vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2017-6929 medium priority: Ubuntu including 1 source packages (drupal7), 20 status rows across 20 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 16, needed 2, ignored 1, released 1. | https://ubuntu.com/security/CVE-2017-6929 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| drupal | drupal | >= 7.0, < 7.57 | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
| drupal | drupal | >= 8.0.0, < 8.4.0 | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* |
| debian | debian_linux | 7.0 | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://lists.debian.org/debian-lts-announce/2018/02/msg00030.html | Issue Tracking |
| https://www.debian.org/security/2018/dsa-4123 | Third Party Advisory |
| https://www.drupal.org/sa-core-2018-001 | Mitigation Vendor Advisory |