CVE-2020-11023

EUVD-2020-0387
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
GitHub_MCNA
6.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
jqueryjquery
1.0.3 ≤
𝑥
< 3.5.0
debiandebian_linux
9.0
drupaldrupal
7.0 ≤
𝑥
< 7.70
drupaldrupal
8.7.0 ≤
𝑥
< 8.7.14
drupaldrupal
8.8.0 ≤
𝑥
< 8.8.6
oracleapplication_express
𝑥
< 20.2
oracleapplication_testing_suite
13.3.0.1
oraclebanking_enterprise_collections
2.7.0 ≤
𝑥
≤ 2.8.0
oraclebanking_platform
2.4.0 ≤
𝑥
≤ 2.10.0
oracleblockchain_platform
𝑥
< 21.1.2
oracleblockchain_platform
21.1.2
oraclebusiness_intelligence
5.9.0.0.0
oraclecommunications_analytics
12.1.1
oraclecommunications_eagle_application_processor
16.1.0 ≤
𝑥
≤ 16.4.0
oraclecommunications_element_manager
8.1.1
oraclecommunications_element_manager
8.2.0
oraclecommunications_element_manager
8.2.1
oraclecommunications_interactive_session_recorder
6.1 ≤
𝑥
≤ 6.4
oraclecommunications_operations_monitor
4.1 ≤
𝑥
≤ 4.3
oraclecommunications_operations_monitor
3.4
oraclecommunications_services_gatekeeper
7.0
oraclecommunications_session_report_manager
8.1.1
oraclecommunications_session_report_manager
8.2.0
oraclecommunications_session_report_manager
8.2.1
oraclecommunications_session_route_manager
8.1.1
oraclecommunications_session_route_manager
8.2.0
oraclecommunications_session_route_manager
8.2.1
oraclefinancial_services_regulatory_reporting_for_de_nederlandsche_bank
8.0.4
oraclefinancial_services_revenue_management_and_billing_analytics
2.7
oraclefinancial_services_revenue_management_and_billing_analytics
2.8
oraclehealth_sciences_inform
6.3.0
oraclehealthcare_translational_research
3.2.1
oraclehealthcare_translational_research
3.3.1
oraclehealthcare_translational_research
3.3.2
oraclehealthcare_translational_research
3.4.0
oraclehyperion_financial_reporting
11.1.2.4
oraclejd_edwards_enterpriseone_orchestrator
𝑥
< 9.2.5.0
oraclejd_edwards_enterpriseone_tools
𝑥
< 9.2.5.0
oracleoss_support_tools
𝑥
< 2.12.41
oraclepeoplesoft_enterprise_human_capital_management_resources
9.2
oracleprimavera_gateway
16.2 ≤
𝑥
≤ 16.2.11
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.7
oracleprimavera_gateway
18.8.0 ≤
𝑥
≤ 18.8.9
oracleprimavera_gateway
19.12.0 ≤
𝑥
≤ 19.12.4
oraclerest_data_services
11.2.0.4
oraclerest_data_services
12.1.0.2
oraclerest_data_services
12.2.0.1
oraclesiebel_mobile
𝑥
≤ 20.12
oraclestoragetek_acsls
8.5.1
oraclestoragetek_tape_analytics_sw_tool
2.3.1
oraclewebcenter_sites
12.2.1.3.0
oraclewebcenter_sites
12.2.1.4.0
oracleweblogic_server
12.1.3.0.0
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph300e_firmware
-
netapph500e_firmware
-
netapph700e_firmware
-
netapph410s_firmware
-
netapph410c_firmware
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappactive_iq_unified_manager
-
netappcloud_backup
-
netappcloud_insights_storage_workload_security_agent
-
netapphci_baseboard_management_controller
-
netappmax_data
-
netapponcommand_insight
-
netapponcommand_system_manager
3.0 ≤
𝑥
≤ 3.1.3
netappsnap_creator_framework
-
netappsnapcenter_server
-
tenablelog_correlation_engine
𝑥
< 6.0.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-jquery
bookworm
3.6.1+dfsg+~3.5.14-1
fixed
bullseye
3.5.1+dfsg+~3.5.5-7
fixed
buster
no-dsa
jessie
not-affected
sid
3.6.1+dfsg+~3.5.14-1
fixed
stretch
ignored
trixie
3.6.1+dfsg+~3.5.14-1
fixed
otrs2
bullseye/non-free
6.0.32-6
fixed
buster
no-dsa
jessie
not-affected
stretch
ignored
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
drupal7
bionic
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
needs-triage
xenial
needs-triage
jquery
bionic
needed
eoan
ignored
focal
needed
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
not-affected
xenial
not-affected
References