Loading
jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.
Use CWE-674, Jquery vendor hub and Jquery product page to widen CVE-2016-10707 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-11023, CVE-2020-11022 and CVE-2020-7656 for nearby disclosures in the same product family.