SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2020-11023

JQuery Cross-Site Scripting (XSS) Vulnerability

KEVMEDIUM 6.1EPSS 83.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 February 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
83.83% probability · 100th percentile
CISA KEV
Listed 23 January 2025 · due 13 February 2025
Weakness
CWE-79
Affected
jquery/jquery · debian/debian linux · fedoraproject/fedora · drupal/drupal · oracle/application express · oracle/application testing suite · oracle/banking enterprise collections · oracle/banking platform · oracle/blockchain platform · oracle/business intelligence · oracle/communications analytics · oracle/communications eagle application processor · oracle/communications element manager · oracle/communications interactive session recorder · oracle/communications operations monitor · oracle/communications services gatekeeper · oracle/communications session report manager · oracle/communications session route manager · oracle/financial services regulatory reporting for de nederlandsche bank · oracle/financial services revenue management and billing analytics · +32 more
Source
security-advisories@github.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6 ; https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2020-11023

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.