CVE-2020-11023
29.04.2020, 21:15
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Vendor | Product | Version |
---|---|---|
jquery | jquery | 1.0.3 ≤ 𝑥 < 3.5.0 |
debian | debian_linux | 9.0 |
drupal | drupal | 7.0 ≤ 𝑥 < 7.70 |
drupal | drupal | 8.7.0 ≤ 𝑥 < 8.7.14 |
drupal | drupal | 8.8.0 ≤ 𝑥 < 8.8.6 |
oracle | application_express | 𝑥 < 20.2 |
oracle | application_testing_suite | 13.3.0.1 |
oracle | banking_enterprise_collections | 2.7.0 ≤ 𝑥 ≤ 2.8.0 |
oracle | banking_platform | 2.4.0 ≤ 𝑥 ≤ 2.10.0 |
oracle | blockchain_platform | 𝑥 < 21.1.2 |
oracle | blockchain_platform | 21.1.2 |
oracle | business_intelligence | 5.9.0.0.0 |
oracle | communications_analytics | 12.1.1 |
oracle | communications_eagle_application_processor | 16.1.0 ≤ 𝑥 ≤ 16.4.0 |
oracle | communications_element_manager | 8.1.1 |
oracle | communications_element_manager | 8.2.0 |
oracle | communications_element_manager | 8.2.1 |
oracle | communications_interactive_session_recorder | 6.1 ≤ 𝑥 ≤ 6.4 |
oracle | communications_operations_monitor | 4.1 ≤ 𝑥 ≤ 4.3 |
oracle | communications_operations_monitor | 3.4 |
oracle | communications_services_gatekeeper | 7.0 |
oracle | communications_session_report_manager | 8.1.1 |
oracle | communications_session_report_manager | 8.2.0 |
oracle | communications_session_report_manager | 8.2.1 |
oracle | communications_session_route_manager | 8.1.1 |
oracle | communications_session_route_manager | 8.2.0 |
oracle | communications_session_route_manager | 8.2.1 |
oracle | financial_services_regulatory_reporting_for_de_nederlandsche_bank | 8.0.4 |
oracle | financial_services_revenue_management_and_billing_analytics | 2.7 |
oracle | financial_services_revenue_management_and_billing_analytics | 2.8 |
oracle | health_sciences_inform | 6.3.0 |
oracle | healthcare_translational_research | 3.2.1 |
oracle | healthcare_translational_research | 3.3.1 |
oracle | healthcare_translational_research | 3.3.2 |
oracle | healthcare_translational_research | 3.4.0 |
oracle | hyperion_financial_reporting | 11.1.2.4 |
oracle | jd_edwards_enterpriseone_orchestrator | 𝑥 < 9.2.5.0 |
oracle | jd_edwards_enterpriseone_tools | 𝑥 < 9.2.5.0 |
oracle | oss_support_tools | 𝑥 < 2.12.41 |
oracle | peoplesoft_enterprise_human_capital_management_resources | 9.2 |
oracle | primavera_gateway | 16.2 ≤ 𝑥 ≤ 16.2.11 |
oracle | primavera_gateway | 17.12.0 ≤ 𝑥 ≤ 17.12.7 |
oracle | primavera_gateway | 18.8.0 ≤ 𝑥 ≤ 18.8.9 |
oracle | primavera_gateway | 19.12.0 ≤ 𝑥 ≤ 19.12.4 |
oracle | rest_data_services | 11.2.0.4 |
oracle | rest_data_services | 12.1.0.2 |
oracle | rest_data_services | 12.2.0.1 |
oracle | siebel_mobile | 𝑥 ≤ 20.12 |
oracle | storagetek_acsls | 8.5.1 |
oracle | storagetek_tape_analytics_sw_tool | 2.3.1 |
oracle | webcenter_sites | 12.2.1.3.0 |
oracle | webcenter_sites | 12.2.1.4.0 |
oracle | weblogic_server | 12.1.3.0.0 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
netapp | h300s_firmware | - |
netapp | h500s_firmware | - |
netapp | h700s_firmware | - |
netapp | h300e_firmware | - |
netapp | h500e_firmware | - |
netapp | h700e_firmware | - |
netapp | h410s_firmware | - |
netapp | h410c_firmware | - |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | cloud_backup | - |
netapp | cloud_insights_storage_workload_security_agent | - |
netapp | hci_baseboard_management_controller | - |
netapp | max_data | - |
netapp | oncommand_insight | - |
netapp | oncommand_system_manager | 3.0 ≤ 𝑥 ≤ 3.1.3 |
netapp | snap_creator_framework | - |
netapp | snapcenter_server | - |
tenable | log_correlation_engine | 𝑥 < 6.0.9 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
drupal7 |
| ||||||||||||||||||||||||||
jquery |
|
References