Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-11023

Опубликовано: 29 апр. 2020
Источник: debian

Описание

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jqueryremovedpackage
jqueryfixed3.3.1~dfsg-3+deb10u1busterpackage
jquerynot-affectedjessiepackage
drupal7removedpackage
drupal7not-affectedjessiepackage
node-jqueryfixed3.5.0+dfsg-2package
node-jqueryno-dsabusterpackage
otrs2fixed6.0.30-1package
otrs2ignoredstretchpackage

Примечания

  • https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6

  • https://www.drupal.org/sa-core-2020-002

  • https://otrs.com/release-notes/otrs-security-advisory-2020-14/

Связанные уязвимости

CVSS3: 6.9
ubuntu
около 5 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.1
redhat
около 5 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVSS3: 6.9
nvd
около 5 лет назад

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

rocky
4 месяца назад

Moderate: gcc-toolset-14-gcc security update

rocky
4 месяца назад

Moderate: gcc-toolset-13-gcc security update