CVE Feed

    Dashboard / CVE / CVE-2020-11023

    CVE-2020-11023

    In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

    Published:Apr 29, 2020
    Last Modified:Nov 7, 2025
    EPS:Apr 29, 2020
    EPSS Score:0.27709
    CVSS Score:6.9

    CISA Notification

    Description

    In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

    Required Action:

    Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Feb 13, 2025
    575 days ago
    Alert Date
    Jan 23, 2025
    596 days ago

    Affected Products

    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Drupal
    Product
    Drupal
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Jquery
    Product
    Jquery
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Cloud Backup
    Vendor
    Netapp
    Product
    Cloud Insights Storage Workload Security Agent
    Vendor
    Netapp
    Product
    H300e
    Vendor
    Netapp
    Product
    H300e Firmware
    Vendor
    Netapp
    Product
    H300s
    Vendor
    Netapp
    Product
    H300s Firmware
    Vendor
    Netapp
    Product
    H410c
    Vendor
    Netapp
    Product
    H410c Firmware
    Vendor
    Netapp
    Product
    H410s
    Vendor
    Netapp
    Product
    H410s Firmware
    Vendor
    Netapp
    Product
    H500e
    Vendor
    Netapp
    Product
    H500e Firmware
    Vendor
    Netapp
    Product
    H500s
    Vendor
    Netapp
    Product
    H500s Firmware
    Vendor
    Netapp
    Product
    H700e
    Vendor
    Netapp
    Product
    H700e Firmware
    Vendor
    Netapp
    Product
    H700s
    Vendor
    Netapp
    Product
    H700s Firmware
    Vendor
    Netapp
    Product
    Hci Baseboard Management Controller
    Vendor
    Netapp
    Product
    Max Data
    Vendor
    Netapp
    Product
    Oncommand Insight
    Vendor
    Netapp
    Product
    Oncommand System Manager
    Vendor
    Netapp
    Product
    Snap Creator Framework
    Vendor
    Netapp
    Product
    Snapcenter Server
    Vendor
    Oracle
    Product
    Application Express
    Vendor
    Oracle
    Product
    Application Testing Suite
    Vendor
    Oracle
    Product
    Banking Enterprise Collections
    Vendor
    Oracle
    Product
    Banking Platform
    Vendor
    Oracle
    Product
    Blockchain Platform
    Vendor
    Oracle
    Product
    Business Intelligence
    Vendor
    Oracle
    Product
    Communications Analytics
    Vendor
    Oracle
    Product
    Communications Eagle Application Processor
    Vendor
    Oracle
    Product
    Communications Element Manager
    Vendor
    Oracle
    Product
    Communications Interactive Session Recorder
    Vendor
    Oracle
    Product
    Communications Operations Monitor
    Vendor
    Oracle
    Product
    Communications Services Gatekeeper
    Vendor
    Oracle
    Product
    Communications Session Report Manager
    Vendor
    Oracle
    Product
    Communications Session Route Manager
    Vendor
    Oracle
    Product
    Financial Services Regulatory Reporting For De Nederlandsche Bank
    Vendor
    Oracle
    Product
    Financial Services Revenue Management And Billing Analytics
    Vendor
    Oracle
    Product
    Health Sciences Inform
    Vendor
    Oracle
    Product
    Healthcare Translational Research
    Vendor
    Oracle
    Product
    Hyperion Financial Reporting
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Orchestrator
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Tools
    Vendor
    Oracle
    Product
    Oss Support Tools
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Human Capital Management Resources
    Vendor
    Oracle
    Product
    Primavera Gateway
    Vendor
    Oracle
    Product
    Rest Data Services
    Vendor
    Oracle
    Product
    Siebel Mobile
    Vendor
    Oracle
    Product
    Storagetek Acsls
    Vendor
    Oracle
    Product
    Storagetek Tape Analytics Sw Tool
    Vendor
    Oracle
    Product
    Webcenter Sites
    Vendor
    Oracle
    Product
    Weblogic Server
    Vendor
    Redhat
    Product
    Amq Interconnect
    Vendor
    Redhat
    Product
    Ansible Tower
    Vendor
    Redhat
    Product
    Discovery
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Jboss Single Sign On
    Vendor
    Redhat
    Product
    Logging
    Vendor
    Redhat
    Product
    Openshift
    Vendor
    Redhat
    Product
    Openstack
    Vendor
    Redhat
    Product
    Quay
    Vendor
    Redhat
    Product
    Red Hat Single Sign On
    Vendor
    Redhat
    Product
    Rhel Aus
    Vendor
    Redhat
    Product
    Rhel E4s
    Vendor
    Redhat
    Product
    Rhel Els
    Vendor
    Redhat
    Product
    Rhel Eus
    Vendor
    Redhat
    Product
    Rhel Tus
    Vendor
    Redhat
    Product
    Rhev Manager
    Vendor
    Redhat
    Product
    Service Mesh
    Vendor
    Tenable
    Product
    Log Correlation Engine

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High