CVE-2020-11022

MEDIUMCVSS 6.1/10EPSS 99.02%

Last modified

CVE-2020-11022 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. EPSS estimates a 99.02% chance of exploitation in the next 30 days.

Description

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Metrics

CVSS 3.1
6.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
99.02%

99.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JqueryJquery>= 1.2, < 3.5.0
DrupalDrupal>= 7.0, < 7.70
DrupalDrupal>= 8.7.0, < 8.7.14
DrupalDrupal>= 8.8.0, < 8.8.6
DebianDebian Linux9.0
FedoraprojectFedora31
FedoraprojectFedora32
FedoraprojectFedora33
OracleAgile Product Lifecycle Management For Process6.2.0.0
OracleApplication Testing Suite13.3.0.1
OracleBanking Digital Experience18.1
OracleBanking Digital Experience18.2
OracleBanking Digital Experience18.3
OracleBanking Digital Experience19.1
OracleBanking Digital Experience19.2
OracleBanking Digital Experience20.1
OracleBlockchain Platform< 21.1.2
OracleCommunications Application Session Controller3.8m0
OracleCommunications Billing And Revenue Management7.5.0.23.0
OracleCommunications Billing And Revenue Management12.0.0.3.0
OracleCommunications Diameter Signaling Router Idih\>= 8.0.0, <= 8.2.2
OracleCommunications Eagle Application Processor>= 16.1.0, <= 16.4.0
OracleCommunications Services Gatekeeper7.0
OracleCommunications Webrtc Session Controller7.2
OracleEnterprise Manager Ops Center12.4.0.0
OracleEnterprise Session Border Controller8.4
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6.0.0, <= 8.1.0.0.0
OracleFinancial Services Analytical Applications Reconciliation Framework>= 8.0.6, <= 8.0.8
OracleFinancial Services Analytical Applications Reconciliation Framework8.1.0
OracleFinancial Services Asset Liability Management8.0.6
OracleFinancial Services Asset Liability Management8.0.7
OracleFinancial Services Asset Liability Management8.1.0
OracleFinancial Services Balance Sheet Planning8.0.8
OracleFinancial Services Basel Regulatory Capital Basic>= 8.0.6, <= 8.0.8
OracleFinancial Services Basel Regulatory Capital Basic8.1.0
OracleFinancial Services Basel Regulatory Capital Internal Ratings Based Approach>= 8.0.6, <= 8.0.8
OracleFinancial Services Basel Regulatory Capital Internal Ratings Based Approach8.1.0
OracleFinancial Services Data Foundation>= 8.0.6, <= 8.1.0
OracleFinancial Services Data Governance For Us Regulatory Reporting>= 8.0.6, <= 8.0.9
OracleFinancial Services Data Integration Hub8.0.6
OracleFinancial Services Data Integration Hub8.0.7
OracleFinancial Services Data Integration Hub8.1.0
OracleFinancial Services Funds Transfer Pricing8.0.6
OracleFinancial Services Funds Transfer Pricing8.0.7
OracleFinancial Services Funds Transfer Pricing8.1.0
OracleFinancial Services Hedge Management And Ifrs Valuations>= 8.0.6, <= 8.0.8
OracleFinancial Services Hedge Management And Ifrs Valuations8.1.0
OracleFinancial Services Institutional Performance Analytics8.0.6
OracleFinancial Services Institutional Performance Analytics8.0.7
OracleFinancial Services Institutional Performance Analytics8.1.0

Showing 50 of 121 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-11022?
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
How severe is CVE-2020-11022?
CVE-2020-11022 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 99.02% probability of exploitation in the next 30 days.
How do I fix CVE-2020-11022?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-11022?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST