CVE-2020-11023
בינונית 6.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- JQuery Cross-Site Scripting (XSS) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 84% (אחוזון 100) נכון ל-31/7/2026
- CWE
- CWE-79
מוצרים מושפעים
jquery: jquery; debian: debian linux; fedoraproject: fedora; drupal: drupal; oracle: application express; oracle: application testing suite; oracle: banking enterprise collections; oracle: banking platform; oracle: blockchain platform; oracle: business intelligence; oracle: communications analytics; oracle: communications eagle application processor; oracle: communications element manager; oracle: communications interactive session recorder; oracle: communications operations monitor
קישורים
- https://blog.jquery.com/2020/04/10/jquery-3-5-0-released Release NotesVendor Advisory
- https://jquery.com/upgrade-guide/3.5/ Release NotesVendor Advisory
- https://blog.jquery.com/2020/04/10/jquery-3-5-0-released Release NotesVendor Advisory
- https://jquery.com/upgrade-guide/3.5/ Release NotesVendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory