CyberICT

CVE-2020-11023

JQuery · Published April 29, 2020

CVSS v3.1

MEDIUM
Patch availableGet patch

Description

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Affected Products

  • Jquery < 3.5.0
  • Debian Linux
  • Fedora
  • Drupal < 7.70

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N