CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
GitHub_MCNA
6.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
jqueryjquery
1.0.3 ≤
𝑥
< 3.5.0
debiandebian_linux
9.0
drupaldrupal
7.0 ≤
𝑥
< 7.70
drupaldrupal
8.7.0 ≤
𝑥
< 8.7.14
drupaldrupal
8.8.0 ≤
𝑥
< 8.8.6
oracleapplication_express
𝑥
< 20.2
oracleapplication_testing_suite
13.3.0.1
oraclebanking_enterprise_collections
2.7.0 ≤
𝑥
≤ 2.8.0
oraclebanking_platform
2.4.0 ≤
𝑥
≤ 2.10.0
oracleblockchain_platform
𝑥
< 21.1.2
oracleblockchain_platform
21.1.2
oraclebusiness_intelligence
5.9.0.0.0
oraclecommunications_analytics
12.1.1
oraclecommunications_eagle_application_processor
16.1.0 ≤
𝑥
≤ 16.4.0
oraclecommunications_element_manager
8.1.1
oraclecommunications_element_manager
8.2.0
oraclecommunications_element_manager
8.2.1
oraclecommunications_interactive_session_recorder
6.1 ≤
𝑥
≤ 6.4
oraclecommunications_operations_monitor
4.1 ≤
𝑥
≤ 4.3
oraclecommunications_operations_monitor
3.4
oraclecommunications_services_gatekeeper
7.0
oraclecommunications_session_report_manager
8.1.1
oraclecommunications_session_report_manager
8.2.0
oraclecommunications_session_report_manager
8.2.1
oraclecommunications_session_route_manager
8.1.1
oraclecommunications_session_route_manager
8.2.0
oraclecommunications_session_route_manager
8.2.1
oraclefinancial_services_regulatory_reporting_for_de_nederlandsche_bank
8.0.4
oraclefinancial_services_revenue_management_and_billing_analytics
2.7
oraclefinancial_services_revenue_management_and_billing_analytics
2.8
oraclehealth_sciences_inform
6.3.0
oraclehealthcare_translational_research
3.2.1
oraclehealthcare_translational_research
3.3.1
oraclehealthcare_translational_research
3.3.2
oraclehealthcare_translational_research
3.4.0
oraclehyperion_financial_reporting
11.1.2.4
oraclejd_edwards_enterpriseone_orchestrator
𝑥
< 9.2.5.0
oraclejd_edwards_enterpriseone_tools
𝑥
< 9.2.5.0
oracleoss_support_tools
𝑥
< 2.12.41
oraclepeoplesoft_enterprise_human_capital_management_resources
9.2
oracleprimavera_gateway
16.2 ≤
𝑥
≤ 16.2.11
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.7
oracleprimavera_gateway
18.8.0 ≤
𝑥
≤ 18.8.9
oracleprimavera_gateway
19.12.0 ≤
𝑥
≤ 19.12.4
oraclerest_data_services
11.2.0.4
oraclerest_data_services
12.1.0.2
oraclerest_data_services
12.2.0.1
oraclesiebel_mobile
𝑥
≤ 20.12
oraclestoragetek_acsls
8.5.1
oraclestoragetek_tape_analytics_sw_tool
2.3.1
oraclewebcenter_sites
12.2.1.3.0
oraclewebcenter_sites
12.2.1.4.0
oracleweblogic_server
12.1.3.0.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph300e_firmware
-
netapph500e_firmware
-
netapph700e_firmware
-
netapph410s_firmware
-
netapph410c_firmware
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappcloud_backup
-
netappcloud_insights_storage_workload_security_agent
-
netapphci_baseboard_management_controller
-
netappmax_data
-
netapponcommand_insight
-
netapponcommand_system_manager
3.0 ≤
𝑥
≤ 3.1.3
netappsnap_creator_framework
-
netappsnapcenter_server
-
tenablelog_correlation_engine
𝑥
< 6.0.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-jquery
bullseye
3.5.1+dfsg+~3.5.5-7
fixed
jessie
not-affected
buster
no-dsa
stretch
ignored
sid
3.6.1+dfsg+~3.5.14-1
fixed
trixie
3.6.1+dfsg+~3.5.14-1
fixed
bookworm
3.6.1+dfsg+~3.5.14-1
fixed
otrs2
bullseye/non-free
6.0.32-6
fixed
jessie
not-affected
buster
no-dsa
stretch
ignored
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
drupal7
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
bionic
dne
xenial
needs-triage
trusty
needs-triage
jquery
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
needed
eoan
ignored
bionic
needed
xenial
not-affected
trusty
not-affected
References