diff --git a/dataprep/eda/create_db_report/layout/bower/jquery/jquery.js b/dataprep/eda/create_db_report/layout/bower/jquery/jquery.js index d2d8ca479..6625ad7cc 100644 --- a/dataprep/eda/create_db_report/layout/bower/jquery/jquery.js +++ b/dataprep/eda/create_db_report/layout/bower/jquery/jquery.js @@ -8712,6 +8712,11 @@ function ajaxConvert( s, response, jqXHR, isSuccess ) { // Convert response if prev dataType is non-auto and differs from current } else if ( prev !== "*" && prev !== current ) { + // Mitigate possible XSS vulnerability (gh-2432) + if ( s.crossDomain && current === "script" ) { + continue; + } + // Seek a direct converter conv = converters[ prev + " " + current ] || converters[ "* " + current ];