MEDIUM · 6.9

CVE-2020-11023

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation me...

Vulnerability Description

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS Score

6.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
JqueryJquery>= 1.0.3, < 3.5.0
DebianDebian Linux9.0
FedoraprojectFedora31
DrupalDrupal>= 7.0, < 7.70
OracleApplication Express< 20.2
OracleApplication Testing Suite13.3.0.1
OracleBanking Enterprise Collections>= 2.7.0, <= 2.8.0
OracleBanking Platform>= 2.4.0, <= 2.10.0
OracleBlockchain Platform< 21.1.2
OracleBusiness Intelligence5.9.0.0.0
OracleCommunications Analytics12.1.1
OracleCommunications Eagle Application Processor>= 16.1.0, <= 16.4.0
OracleCommunications Element Manager8.1.1
OracleCommunications Interactive Session Recorder>= 6.1, <= 6.4
OracleCommunications Operations Monitor>= 4.1, <= 4.3
OracleCommunications Services Gatekeeper7.0
OracleCommunications Session Report Manager8.1.1
OracleCommunications Session Route Manager8.1.1
OracleFinancial Services Regulatory Reporting For De Nederlandsche Bank8.0.4
OracleFinancial Services Revenue Management And Billing Analytics2.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11023?

CVE-2020-11023 is a vulnerability with a CVSS score of 6.9 (MEDIUM). In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation me...

How severe is CVE-2020-11023?

CVE-2020-11023 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11023?

Check the references section above for vendor advisories and patch information. Affected products include: Jquery Jquery, Debian Debian Linux, Fedoraproject Fedora, Drupal Drupal, Oracle Application Express.