SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11022

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.

MEDIUM 6.1EPSS 99.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 99.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
99.02% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
jquery/jquery · drupal/drupal · debian/debian linux · fedoraproject/fedora · oracle/agile product lifecycle management for process · oracle/application testing suite · oracle/banking digital experience · oracle/blockchain platform · oracle/communications application session controller · oracle/communications billing and revenue management · oracle/communications diameter signaling router idih\ · oracle/communications eagle application processor · oracle/communications services gatekeeper · oracle/communications webrtc session controller · oracle/enterprise manager ops center · oracle/enterprise session border controller · oracle/financial services analytical applications infrastructure · oracle/financial services analytical applications reconciliation framework · oracle/financial services asset liability management · oracle/financial services balance sheet planning · +40 more
Source
security-advisories@github.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.