CVE-2020-11022
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Affected (121)
Show all products
Jquery: Jquery · Drupal: Drupal · Debian: Debian Linux · Fedoraproject: Fedora · Oracle: Agile Product Lifecycle Management For Process, Application Testing Suite, Banking Digital Experience, Blockchain Platform, Communications Eagle Application Processor, Communications Services Gatekeeper, Financial Services Analytical Applications Infrastructure, Hospitality Simphony, Insurance Data Foundation, Storagetek Acsls, Agile Product Supplier Collaboration For Process, Communications Application Session Controller, Communications Billing And Revenue Management, Communications Diameter Signaling Router Idih\, Communications Webrtc Session Controller, Enterprise Manager Ops Center, Enterprise Session Border Controller, Financial Services Analytical Applications Reconciliation Framework, Financial Services Asset Liability Management, Financial Services Balance Sheet Planning, Financial Services Basel Regulatory Capital Basic, Financial Services Basel Regulatory Capital Internal Ratings Based Approach, Financial Services Data Foundation, Financial Services Data Governance For Us Regulatory Reporting, Financial Services Data Integration Hub, Financial Services Funds Transfer Pricing, Financial Services Hedge Management And Ifrs Valuations, Financial Services Institutional Performance Analytics, Financial Services Liquidity Risk Management, Financial Services Liquidity Risk Measurement And Management, Financial Services Loan Loss Forecasting And Provisioning, Financial Services Market Risk Measurement And Management, Financial Services Price Creation And Discovery, Financial Services Profitability Management, Financial Services Regulatory Reporting For European Banking Authority, Financial Services Regulatory Reporting For Us Federal Reserve, Healthcare Foundation, Hospitality Materials Control, Insurance Accounting Analyzer, Insurance Allocation Manager For Enterprise Profitability, Insurance Insbridge Rating And Underwriting, Jdeveloper, Peoplesoft Enterprise Peopletools, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Retail Back Office, Retail Customer Management And Segmentation Foundation, Retail Returns Management, Siebel Ui Framework, Weblogic Server · Netapp: Max Data, Oncommand Insight, Oncommand System Manager, Snap Creator Framework, Snapcenter, H300s Firmware, H500s Firmware, H700s Firmware, H300e Firmware, H500e Firmware, H700e Firmware, H410s Firmware, H410c Firmware · Opensuse: Leap · Tenable: Log Correlation Engine
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 31 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.0.0 | |
| Version 13.3.0.1 | |
| Version 18.1 | |
| Before 21.1.2 | |
| From 16.1.0 to 16.4.0 | |
| Version 7.0 | |
| From 8.0.6.0.0 to 8.1.0.0.0 | |
| From 19.1.0 to 19.1.2 | |
| From 8.0.6 to 8.1.0 | |
| Version 8.5.1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| From 3.0 to 3.1.3 | |
| All versions | |
| All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300s | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500s | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700s | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300e | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500e | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700e | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410s | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410c | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.9 |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.0.0 | |
| From 18.1 to 20.1 | |
| Version 3.8m0 | |
| Version 12.0.0.3.0 | |
| From 8.0.0 to 8.2.2 | |
| Version 7.2 | |
| Version 12.4.0.0 | |
| Version 8.4 | |
| From 8.0.6 to 8.1.0 | |
| From 8.0.6 to 8.0.8 | |
| Version 8.0.6 | |
| Version 8.0.8 | |
| From 8.0.6 to 8.0.8 | |
| From 8.0.6 to 8.0.8 | |
| From 8.0.6 to 8.1.0 | |
| From 8.0.6 to 8.0.9 | |
| Version 8.0.6 | |
| Version 8.0.6 | |
| From 8.0.6 to 8.0.8 | |
| Version 8.0.6 | |
| Version 8.0.6 | |
| Version 8.0.7 | |
| From 8.0.6 to 8.0.8 | |
| Version 8.0.6 | |
| Version 8.0.6 | |
| Version 8.0.6 | |
| From 8.0.6 to 8.1.0 | |
| From 8.0.6 to 8.0.9 | |
| Version 7.1.1 | |
| Version 18.1 | |
| Version 18.1 | |
| Version 8.0.9 | |
| Version 8.0.8 | |
| Version 8.0.6-8.1.0 | |
| From 5.0.0.0 to 5.6.0.0 | |
| Version 11.1.1.9.0 | |
| Version 8.56 | |
| From 12.2.0 to 12.2.20 | |
| Version 10.4.6 | |
| From 12.2.0 to 12.2.20 | |
| Version 14.0 | |
| Version 19.0 | |
| Version 14.0 | |
| Version 20.8 | |
| Version 10.3.6.0.0 |
References (90)
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Source: security-advisories@github.com
MitigationThird Party Advisory
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Source: security-advisories@github.com
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.