Lucene search

K
nvd[email protected]NVD:CVE-2020-11023
HistoryApr 29, 2020 - 9:15 p.m.

CVE-2020-11023

2020-04-2921:15:11
CWE-79
web.nvd.nist.gov
1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

7.2 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.6%

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery’s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Affected configurations

NVD
Node
jqueryjqueryRange1.0.33.5.0
Node
debiandebian_linuxMatch9.0
Node
fedoraprojectfedoraMatch31
OR
fedoraprojectfedoraMatch32
OR
fedoraprojectfedoraMatch33
Node
drupaldrupalRange7.07.70
OR
drupaldrupalRange8.7.08.7.14
OR
drupaldrupalRange8.8.08.8.6
Node
oracleapplication_expressRange<20.2
OR
oracleapplication_testing_suiteMatch13.3.0.1
OR
oraclebanking_enterprise_collectionsRange2.7.02.8.0
OR
oraclebanking_platformRange2.4.02.10.0
OR
oraclebusiness_intelligenceMatch5.9.0.0.0enterprise
OR
oraclecommunications_analyticsMatch12.1.1
OR
oraclecommunications_eagle_application_processorRange16.1.016.4.0
OR
oraclecommunications_element_managerMatch8.1.1
OR
oraclecommunications_element_managerMatch8.2.0
OR
oraclecommunications_element_managerMatch8.2.1
OR
oraclecommunications_interactive_session_recorderRange6.16.4
OR
oraclecommunications_operations_monitorRange4.14.3
OR
oraclecommunications_operations_monitorMatch3.4
OR
oraclecommunications_services_gatekeeperMatch7.0
OR
oraclecommunications_session_report_managerMatch8.1.1
OR
oraclecommunications_session_report_managerMatch8.2.0
OR
oraclecommunications_session_report_managerMatch8.2.1
OR
oraclecommunications_session_route_managerMatch8.1.1
OR
oraclecommunications_session_route_managerMatch8.2.0
OR
oraclecommunications_session_route_managerMatch8.2.1
OR
oraclefinancial_services_regulatory_reporting_for_de_nederlandsche_bankMatch8.0.4
OR
oraclefinancial_services_revenue_management_and_billing_analyticsMatch2.7
OR
oraclefinancial_services_revenue_management_and_billing_analyticsMatch2.8
OR
oraclehealth_sciences_informMatch6.3.0
OR
oraclehealthcare_translational_researchMatch3.2.1
OR
oraclehealthcare_translational_researchMatch3.3.1
OR
oraclehealthcare_translational_researchMatch3.3.2
OR
oraclehealthcare_translational_researchMatch3.4.0
OR
oraclehyperion_financial_reportingMatch11.1.2.4
OR
oraclejd_edwards_enterpriseone_orchestratorRange<9.2.5.0
OR
oraclejd_edwards_enterpriseone_toolsRange<9.2.5.0
OR
oracleoss_support_toolsRange<2.12.41
OR
oraclepeoplesoft_enterprise_human_capital_management_resourcesMatch9.2
OR
oracleprimavera_gatewayRange16.216.2.11
OR
oracleprimavera_gatewayRange17.12.017.12.7
OR
oracleprimavera_gatewayRange18.8.018.8.9
OR
oracleprimavera_gatewayRange19.12.019.12.4
OR
oraclerest_data_servicesMatch11.2.0.4-
OR
oraclerest_data_servicesMatch12.1.0.2-
OR
oraclerest_data_servicesMatch12.2.0.1-
OR
oraclerest_data_servicesMatch18c-
OR
oraclerest_data_servicesMatch19c-
OR
oraclesiebel_mobileRange20.12
OR
oraclestoragetek_acslsMatch8.5.1
OR
oraclestoragetek_tape_analytics_sw_toolMatch2.3.1
OR
oraclewebcenter_sitesMatch12.2.1.3.0
OR
oraclewebcenter_sitesMatch12.2.1.4.0
OR
oracleweblogic_serverMatch12.1.3.0.0
OR
oracleweblogic_serverMatch12.2.1.3.0
OR
oracleweblogic_serverMatch12.2.1.4.0
OR
oracleweblogic_serverMatch14.1.1.0.0
Node
netapph300s_firmwareMatch-
AND
netapph300sMatch-
Node
netapph500s_firmwareMatch-
AND
netapph500sMatch-
Node
netapph700s_firmwareMatch-
AND
netapph700sMatch-
Node
netapph300e_firmwareMatch-
AND
netapph300eMatch-
Node
netapph500e_firmwareMatch-
AND
netapph500eMatch-
Node
netapph700e_firmwareMatch-
AND
netapph700eMatch-
Node
netapph410s_firmwareMatch-
AND
netapph410sMatch-
Node
netapph410c_firmwareMatch-
AND
netapph410cMatch-
Node
netappmax_dataMatch-
OR
netapponcommand_insightMatch-
OR
netapponcommand_system_managerRange3.03.1.3
OR
netappsnap_creator_frameworkMatch-
OR
netappsnapcenter_serverMatch-
Node
tenablelog_correlation_engineRange<6.0.9

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

7.2 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.6%