Vulnerability Description
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jquery | Jquery | < 1.9.0 |
| Oracle | Peoplesoft Enterprise Peopletools | 8.58 |
| Netapp | Active Iq Unified Manager | - |
| Netapp | Cloud Backup | - |
| Netapp | Oncommand System Manager | >= 3.0.0, <= 3.1.3 |
| Netapp | Snap Creator Framework | - |
| Juniper | Junos | 21.2 |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20200528-0001/Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JQUERY-569619ExploitThird Party Advisory
- https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-MThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200528-0001/Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JQUERY-569619ExploitThird Party Advisory
- https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-MThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlThird Party Advisory
FAQ
What is CVE-2020-7656?
CVE-2020-7656 is a vulnerability with a CVSS score of 6.1 (MEDIUM). jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >"...
How severe is CVE-2020-7656?
CVE-2020-7656 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7656?
Check the references section above for vendor advisories and patch information. Affected products include: Jquery Jquery, Oracle Peoplesoft Enterprise Peopletools, Netapp Active Iq Unified Manager, Netapp Cloud Backup, Netapp Oncommand System Manager.