ZeroHour

CVE-2020-11022

CVSS 3.1
6.1 medium
EPSS
99%p100
Published
()
Modified
Description

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Vendors
jquerydrupaldebianfedoraprojectoraclenetappopensusetenable
Products
jquery, drupal, debian linux, fedora, agile product lifecycle management for process, application testing suite, banking digital experience, blockchain platform, communications application session controller, communications billing and revenue management, communications diameter signaling router idih\, communications eagle application processor
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news