Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-11023


In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.


Published

2020-04-29T21:15:11.743

Last Modified

2025-04-04T19:53:43.140

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jquery jquery < 3.5.0 Yes
Operating System debian debian_linux 9.0 Yes
Operating System fedoraproject fedora 31 Yes
Operating System fedoraproject fedora 32 Yes
Operating System fedoraproject fedora 33 Yes
Application drupal drupal < 7.70 Yes
Application drupal drupal < 8.7.14 Yes
Application drupal drupal < 8.8.6 Yes
Application oracle application_express < 20.2 Yes
Application oracle application_testing_suite 13.3.0.1 Yes
Application oracle banking_enterprise_collections ≤ 2.8.0 Yes
Application oracle banking_platform ≤ 2.10.0 Yes
Application oracle blockchain_platform < 21.1.2 Yes
Application oracle blockchain_platform 21.1.2 Yes
Application oracle business_intelligence 5.9.0.0.0 Yes
Application oracle communications_analytics 12.1.1 Yes
Application oracle communications_eagle_application_processor ≤ 16.4.0 Yes
Application oracle communications_element_manager 8.1.1 Yes
Application oracle communications_element_manager 8.2.0 Yes
Application oracle communications_element_manager 8.2.1 Yes
Application oracle communications_interactive_session_recorder ≤ 6.4 Yes
Application oracle communications_operations_monitor ≤ 4.3 Yes
Application oracle communications_operations_monitor 3.4 Yes
Application oracle communications_services_gatekeeper 7.0 Yes
Application oracle communications_session_report_manager 8.1.1 Yes
Application oracle communications_session_report_manager 8.2.0 Yes
Application oracle communications_session_report_manager 8.2.1 Yes
Application oracle communications_session_route_manager 8.1.1 Yes
Application oracle communications_session_route_manager 8.2.0 Yes
Application oracle communications_session_route_manager 8.2.1 Yes
Application oracle financial_services_regulatory_reporting_for_de_nederlandsche_bank 8.0.4 Yes
Application oracle financial_services_revenue_management_and_billing_analytics 2.7 Yes
Application oracle financial_services_revenue_management_and_billing_analytics 2.8 Yes
Application oracle health_sciences_inform 6.3.0 Yes
Application oracle healthcare_translational_research 3.2.1 Yes
Application oracle healthcare_translational_research 3.3.1 Yes
Application oracle healthcare_translational_research 3.3.2 Yes
Application oracle healthcare_translational_research 3.4.0 Yes
Application oracle hyperion_financial_reporting 11.1.2.4 Yes
Application oracle jd_edwards_enterpriseone_orchestrator < 9.2.5.0 Yes
Application oracle jd_edwards_enterpriseone_tools < 9.2.5.0 Yes
Application oracle oss_support_tools < 2.12.41 Yes
Application oracle peoplesoft_enterprise_human_capital_management_resources 9.2 Yes
Application oracle primavera_gateway ≤ 16.2.11 Yes
Application oracle primavera_gateway ≤ 17.12.7 Yes
Application oracle primavera_gateway ≤ 18.8.9 Yes
Application oracle primavera_gateway ≤ 19.12.4 Yes
Application oracle rest_data_services 11.2.0.4 Yes
Application oracle rest_data_services 12.1.0.2 Yes
Application oracle rest_data_services 12.2.0.1 Yes
Application oracle rest_data_services 18c Yes
Application oracle rest_data_services 19c Yes
Application oracle siebel_mobile ≤ 20.12 Yes
Application oracle storagetek_acsls 8.5.1 Yes
Application oracle storagetek_tape_analytics_sw_tool 2.3.1 Yes
Application oracle webcenter_sites 12.2.1.3.0 Yes
Application oracle webcenter_sites 12.2.1.4.0 Yes
Application oracle weblogic_server 12.1.3.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Application oracle weblogic_server 14.1.1.0.0 Yes
Operating System netapp h300s_firmware - Yes
Hardware netapp h300s - No
Operating System netapp h500s_firmware - Yes
Hardware netapp h500s - No
Operating System netapp h700s_firmware - Yes
Hardware netapp h700s - No
Operating System netapp h300e_firmware - Yes
Hardware netapp h300e - No
Operating System netapp h500e_firmware - Yes
Hardware netapp h500e - No
Operating System netapp h700e_firmware - Yes
Hardware netapp h700e - No
Operating System netapp h410s_firmware - Yes
Hardware netapp h410s - No
Operating System netapp h410c_firmware - Yes
Hardware netapp h410c - No
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp cloud_backup - Yes
Application netapp cloud_insights_storage_workload_security_agent - Yes
Application netapp hci_baseboard_management_controller - Yes
Application netapp max_data - Yes
Application netapp oncommand_insight - Yes
Application netapp oncommand_system_manager ≤ 3.1.3 Yes
Application netapp snap_creator_framework - Yes
Application netapp snapcenter_server - Yes
Application tenable log_correlation_engine < 6.0.9 Yes

References