MEDIUM · 6.9

CVE-2020-11022

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may ...

Vulnerability Description

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS Score

6.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
JqueryJquery>= 1.2, < 3.5.0
DrupalDrupal>= 7.0, < 7.70
DebianDebian Linux9.0
FedoraprojectFedora31
OracleAgile Product Lifecycle Management For Process6.2.0.0
OracleApplication Testing Suite13.3.0.1
OracleBanking Digital Experience18.1
OracleBlockchain Platform< 21.1.2
OracleCommunications Application Session Controller3.8m0
OracleCommunications Billing And Revenue Management7.5.0.23.0
OracleCommunications Diameter Signaling Router Idih\>= 8.0.0, <= 8.2.2,
OracleCommunications Eagle Application Processor>= 16.1.0, <= 16.4.0
OracleCommunications Services Gatekeeper7.0
OracleCommunications Webrtc Session Controller7.2
OracleEnterprise Manager Ops Center12.4.0.0
OracleEnterprise Session Border Controller8.4
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6.0.0, <= 8.1.0.0.0
OracleFinancial Services Analytical Applications Reconciliation Framework>= 8.0.6, <= 8.0.8
OracleFinancial Services Asset Liability Management8.0.6
OracleFinancial Services Balance Sheet Planning8.0.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11022?

CVE-2020-11022 is a vulnerability with a CVSS score of 6.9 (MEDIUM). In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may ...

How severe is CVE-2020-11022?

CVE-2020-11022 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11022?

Check the references section above for vendor advisories and patch information. Affected products include: Jquery Jquery, Drupal Drupal, Debian Debian Linux, Fedoraproject Fedora, Oracle Agile Product Lifecycle Management For Process.