← All CVEs

CVE-2020-11023

medium · 6.9Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2025-01-23Remediation due 2025-02-13

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

6.9
CVSS
84.9%
EPSS (exploit prob.)
100th
EPSS percentile
2020-04-29
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
jqueryjquery>= 1.0.3, < 3.5.0
debiandebian_linux9.0
fedoraprojectfedora31
fedoraprojectfedora32
fedoraprojectfedora33
drupaldrupal>= 7.0, < 7.70
drupaldrupal>= 8.7.0, < 8.7.14
drupaldrupal>= 8.8.0, < 8.8.6
oracleapplication_express< 20.2
oracleapplication_testing_suite13.3.0.1
oraclebanking_enterprise_collections>= 2.7.0, <= 2.8.0
oraclebanking_platform>= 2.4.0, <= 2.10.0
oracleblockchain_platform< 21.1.2
oracleblockchain_platform21.1.2
oraclebusiness_intelligence5.9.0.0.0
oraclecommunications_analytics12.1.1
oraclecommunications_eagle_application_processor>= 16.1.0, <= 16.4.0
oraclecommunications_element_manager8.1.1
oraclecommunications_element_manager8.2.0
oraclecommunications_element_manager8.2.1
oraclecommunications_interactive_session_recorder>= 6.1, <= 6.4
oraclecommunications_operations_monitor>= 4.1, <= 4.3
oraclecommunications_operations_monitor3.4
oraclecommunications_services_gatekeeper7.0
oraclecommunications_session_report_manager8.1.1
oraclecommunications_session_report_manager8.2.0
oraclecommunications_session_report_manager8.2.1
oraclecommunications_session_route_manager8.1.1
oraclecommunications_session_route_manager8.2.0
oraclecommunications_session_route_manager8.2.1
oraclefinancial_services_regulatory_reporting_for_de_nederlandsche_bank8.0.4
oraclefinancial_services_revenue_management_and_billing_analytics2.7
oraclefinancial_services_revenue_management_and_billing_analytics2.8
oraclehealth_sciences_inform6.3.0
oraclehealthcare_translational_research3.2.1
oraclehealthcare_translational_research3.3.1
oraclehealthcare_translational_research3.3.2
oraclehealthcare_translational_research3.4.0
oraclehyperion_financial_reporting11.1.2.4
oraclejd_edwards_enterpriseone_orchestrator< 9.2.5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-11023