← Back

CVE-2020-11023

nvd nist
Published: Apr 29, 2020Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Affected (81)

Products: Jquery: Jquery · Debian: Debian Linux · Fedoraproject: Fedora · +4 more
Show all products
1 product
Jquery
1 product
Debian Linux
1 product
Fedora
1 product
Drupal
30 products
Application Express
Application Testing Suite
Banking Enterprise Collections
Banking Platform
Blockchain Platform
Business Intelligence
Communications Analytics
Communications Element Manager
Communications Operations Monitor
Health Sciences Inform
Healthcare Translational Research
Hyperion Financial Reporting
Jd Edwards Enterpriseone Tools
Oss Support Tools
Primavera Gateway
Rest Data Services
Siebel Mobile
Storagetek Acsls
Storagetek Tape Analytics Sw Tool
Webcenter Sites
Weblogic Server
17 products
H300s Firmware
H500s Firmware
H700s Firmware
H300e Firmware
H500e Firmware
H700e Firmware
H410s Firmware
H410c Firmware
Active Iq Unified Manager
Cloud Backup
Max Data
Oncommand Insight
Oncommand System Manager
Snap Creator Framework
Snapcenter Server
1 product
Log Correlation Engine
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.3 to 3.5.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 32
Version 33
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
From 7.0 to 7.70
From 8.7.0 to 8.7.14
From 8.8.0 to 8.8.6
Configuration E
53 vulnerable
Vulnerable SoftwareAffected Versions
Before 20.2
Version 13.3.0.1
From 2.7.0 to 2.8.0
From 2.4.0 to 2.10.0
Oracle
Before 21.1.2
Version 21.1.2
Version 5.9.0.0.0
Version 12.1.1
From 16.1.0 to 16.4.0
Oracle
Version 8.1.1
Version 8.2.0
Version 8.2.1
From 6.1 to 6.4
Oracle
From 4.1 to 4.3
Version 3.4
Version 7.0
Oracle
Version 8.1.1
Version 8.2.0
Version 8.2.1
Oracle
Version 8.1.1
Version 8.2.0
Version 8.2.1
Version 8.0.4
Oracle
Version 2.7
Version 2.8
Version 6.3.0
Oracle
Version 3.2.1
Version 3.3.1
Version 3.3.2
Version 3.4.0
Version 11.1.2.4
Before 9.2.5.0
Before 9.2.5.0
Before 2.12.41
Version 9.2
Oracle
From 16.2 to 16.2.11
From 17.12.0 to 17.12.7
From 18.8.0 to 18.8.9
From 19.12.0 to 19.12.4
Oracle
Version 11.2.0.4
Version 12.1.0.2
Version 12.2.0.1
Version 18c
Version 19c
Up to 20.12
Version 8.5.1
Version 2.3.1
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300s
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500s
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700s
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300e
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500e
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700e
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410s
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410c
All versions
Configuration N
11 vulnerable
Configuration O
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.0.9

References (132)

Source: security-advisories@github.com
Broken LinkMailing ListThird Party Advisory
Source: security-advisories@github.com
ExploitThird Party AdvisoryVDB Entry
Source: security-advisories@github.com
Release NotesVendor Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Release NotesVendor Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.