← All CVEs

CVE-2020-11022

medium · 6.9

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

6.9
CVSS
99.2%
EPSS (exploit prob.)
100th
EPSS percentile
2020-04-29
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
jqueryjquery>= 1.2, < 3.5.0
drupaldrupal>= 7.0, < 7.70
drupaldrupal>= 8.7.0, < 8.7.14
drupaldrupal>= 8.8.0, < 8.8.6
debiandebian_linux9.0
fedoraprojectfedora31
fedoraprojectfedora32
fedoraprojectfedora33
oracleagile_product_lifecycle_management_for_process6.2.0.0
oracleapplication_testing_suite13.3.0.1
oraclebanking_digital_experience18.1
oraclebanking_digital_experience18.2
oraclebanking_digital_experience18.3
oraclebanking_digital_experience19.1
oraclebanking_digital_experience19.2
oraclebanking_digital_experience20.1
oracleblockchain_platform< 21.1.2
oraclecommunications_application_session_controller3.8m0
oraclecommunications_billing_and_revenue_management7.5.0.23.0
oraclecommunications_billing_and_revenue_management12.0.0.3.0
oraclecommunications_diameter_signaling_router_idih:>= 8.0.0, <= 8.2.2
oraclecommunications_eagle_application_processor>= 16.1.0, <= 16.4.0
oraclecommunications_services_gatekeeper7.0
oraclecommunications_webrtc_session_controller7.2
oracleenterprise_manager_ops_center12.4.0.0
oracleenterprise_session_border_controller8.4
oraclefinancial_services_analytical_applications_infrastructure>= 8.0.6.0.0, <= 8.1.0.0.0
oraclefinancial_services_analytical_applications_reconciliation_framework>= 8.0.6, <= 8.0.8
oraclefinancial_services_analytical_applications_reconciliation_framework8.1.0
oraclefinancial_services_asset_liability_management8.0.6
oraclefinancial_services_asset_liability_management8.0.7
oraclefinancial_services_asset_liability_management8.1.0
oraclefinancial_services_balance_sheet_planning8.0.8
oraclefinancial_services_basel_regulatory_capital_basic>= 8.0.6, <= 8.0.8
oraclefinancial_services_basel_regulatory_capital_basic8.1.0
oraclefinancial_services_basel_regulatory_capital_internal_ratings_based_approach>= 8.0.6, <= 8.0.8
oraclefinancial_services_basel_regulatory_capital_internal_ratings_based_approach8.1.0
oraclefinancial_services_data_foundation>= 8.0.6, <= 8.1.0
oraclefinancial_services_data_governance_for_us_regulatory_reporting>= 8.0.6, <= 8.0.9
oraclefinancial_services_data_integration_hub8.0.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-11022