CVE-2020-11023
JQuery · Published April 29, 2020
6.1
CVSS v3.1
MEDIUMCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Affected Products
- Jquery < 3.5.0
- Debian Linux
- Fedora
- Drupal < 7.70
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N