CVE-2020-11023

Summary

CVECVE-2020-11023
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2020-04-29 21:15:00 UTC
Updated2023-11-07 03:14:00 UTC
DescriptionIn jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Risk And Classification

EPSS: 0.368510000 probability, percentile 0.971170000 (date 2026-04-01)

CISA KEV: Listed on 2025-01-23; due 2025-02-13; ransomware use Unknown

Problem Types: CWE-79

CISA Known Exploited Vulnerability

VendorJQuery
ProductJQuery
NameJQuery Cross-Site Scripting (XSS) Vulnerability
Required ActionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
NotesThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6 ; https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2020-11023

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Debian Debian Linux 9.0 All All All
Operating System Debian Debian Linux 9.0 All All All
Application Drupal Drupal All All All All
Application Drupal Drupal All All All All
Operating System Fedoraproject Fedora 31 All All All
Operating System Fedoraproject Fedora 32 All All All
Operating System Fedoraproject Fedora 33 All All All
Operating System Fedoraproject Fedora 31 All All All
Operating System Fedoraproject Fedora 32 All All All
Operating System Fedoraproject Fedora 33 All All All
Application Jquery Jquery All All All All
Application Jquery Jquery All All All All
Hardware Netapp H300e - All All All
Hardware Netapp H300e - All All All
Operating System Netapp H300e Firmware - All All All
Operating System Netapp H300e Firmware - All All All
Hardware Netapp H300s - All All All
Hardware Netapp H300s - All All All
Operating System Netapp H300s Firmware - All All All
Operating System Netapp H300s Firmware - All All All
Hardware Netapp H410c - All All All
Hardware Netapp H410c - All All All
Operating System Netapp H410c Firmware - All All All
Operating System Netapp H410c Firmware - All All All
Hardware Netapp H410s - All All All
Hardware Netapp H410s - All All All
Operating System Netapp H410s Firmware - All All All
Operating System Netapp H410s Firmware - All All All
Hardware Netapp H500e - All All All
Hardware Netapp H500e - All All All
Operating System Netapp H500e Firmware - All All All
Operating System Netapp H500e Firmware - All All All
Hardware Netapp H500s - All All All
Hardware Netapp H500s - All All All
Operating System Netapp H500s Firmware - All All All
Operating System Netapp H500s Firmware - All All All
Hardware Netapp H700e - All All All
Hardware Netapp H700e - All All All
Operating System Netapp H700e Firmware - All All All
Operating System Netapp H700e Firmware - All All All
Hardware Netapp H700s - All All All
Hardware Netapp H700s - All All All
Operating System Netapp H700s Firmware - All All All
Operating System Netapp H700s Firmware - All All All
Application Netapp Max Data - All All All
Application Netapp Oncommand Insight - All All All
Application Netapp Oncommand Insight - All All All
Application Netapp Oncommand System Manager All All All All
Application Netapp Snapcenter Server - All All All
Application Netapp Snapcenter Server - All All All
Application Netapp Snap Creator Framework - All All All
Application Netapp Snap Creator Framework - All All All
Application Opensuse Backports Sle 15.0 sp1 All All
Application Opensuse Backports Sle 15.0 sp2 All All
Application Opensuse Backports Sle 15.0 sp1 All All
Application Opensuse Backports Sle 15.0 sp2 All All
Operating System Opensuse Leap 15.1 All All All
Operating System Opensuse Leap 15.2 All All All
Operating System Opensuse Leap 15.1 All All All
Operating System Opensuse Leap 15.2 All All All
Application Oracle Application Express All All All All
Application Oracle Application Express All All All All
Application Oracle Application Testing Suite 13.3.0.1 All All All
Application Oracle Application Testing Suite 13.3.0.1 All All All
Application Oracle Banking Enterprise Collections All All All All
Application Oracle Banking Platform All All All All
Application Oracle Business Intelligence 5.9.0.0.0 All All All
Application Oracle Communications Analytics 12.1.1 All All All
Application Oracle Communications Analytics 12.1.1 All All All
Application Oracle Communications Eagle Application Processor All All All All
Application Oracle Communications Element Manager 8.1.1 All All All
Application Oracle Communications Element Manager 8.2.0 All All All
Application Oracle Communications Element Manager 8.2.1 All All All
Application Oracle Communications Element Manager 8.1.1 All All All
Application Oracle Communications Element Manager 8.2.0 All All All
Application Oracle Communications Element Manager 8.2.1 All All All
Application Oracle Communications Interactive Session Recorder All All All All
Application Oracle Communications Operations Monitor 3.4 All All All
Application Oracle Communications Operations Monitor 3.4 All All All
Application Oracle Communications Operations Monitor All All All All
Application Oracle Communications Services Gatekeeper 7.0 All All All
Application Oracle Communications Session Report Manager 8.1.1 All All All
Application Oracle Communications Session Report Manager 8.2.0 All All All
Application Oracle Communications Session Report Manager 8.2.1 All All All
Application Oracle Communications Session Report Manager 8.1.1 All All All
Application Oracle Communications Session Report Manager 8.2.0 All All All
Application Oracle Communications Session Report Manager 8.2.1 All All All
Application Oracle Communications Session Route Manager 8.1.1 All All All
Application Oracle Communications Session Route Manager 8.2.0 All All All
Application Oracle Communications Session Route Manager 8.2.1 All All All
Application Oracle Communications Session Route Manager 8.1.1 All All All
Application Oracle Communications Session Route Manager 8.2.0 All All All
Application Oracle Communications Session Route Manager 8.2.1 All All All
Application Oracle Financial Services Regulatory Reporting For De Nederlandsche Bank 8.0.4 All All All
Application Oracle Financial Services Regulatory Reporting For De Nederlandsche Bank 8.0.4 All All All
Application Oracle Financial Services Revenue Management And Billing Analytics 2.7 All All All
Application Oracle Financial Services Revenue Management And Billing Analytics 2.8 All All All
Application Oracle Healthcare Translational Research 3.2.1 All All All
Application Oracle Healthcare Translational Research 3.3.1 All All All
Application Oracle Healthcare Translational Research 3.3.2 All All All
Application Oracle Healthcare Translational Research 3.4.0 All All All
Application Oracle Healthcare Translational Research 3.2.1 All All All
Application Oracle Healthcare Translational Research 3.3.1 All All All
Application Oracle Healthcare Translational Research 3.3.2 All All All
Application Oracle Healthcare Translational Research 3.4.0 All All All
Application Oracle Health Sciences Inform 6.3.0 All All All
Application Oracle Health Sciences Inform 63.0 All All All
Application Oracle Hyperion Financial Reporting 11.1.2.4 All All All
Application Oracle Hyperion Financial Reporting 11.1.2.4 All All All
Application Oracle Jd Edwards Enterpriseone Orchestrator All All All All
Application Oracle Jd Edwards Enterpriseone Orchestrator All All All All
Application Oracle Jd Edwards Enterpriseone Tools All All All All
Application Oracle Jd Edwards Enterpriseone Tools All All All All
Application Oracle Oss Support Tools All All All All
Application Oracle Peoplesoft Enterprise Human Capital Management Resources 9.2 All All All
Application Oracle Peoplesoft Enterprise Human Capital Management Resources 9.2 All All All
Application Oracle Primavera Gateway All All All All
Application Oracle Primavera Gateway All All All All
Application Oracle Primavera Gateway All All All All
Application Oracle Primavera Gateway All All All All
Application Oracle Rest Data Services 11.2.0.4 All All All
Application Oracle Rest Data Services 12.1.0.2 All All All
Application Oracle Rest Data Services 12.2.0.1 All All All
Application Oracle Rest Data Services 18c All All All
Application Oracle Rest Data Services 19c All All All
Application Oracle Rest Data Services 11.2.0.4 All All All
Application Oracle Rest Data Services 12.1.0.2 All All All
Application Oracle Rest Data Services 12.2.0.1 All All All
Application Oracle Rest Data Services 18c All All All
Application Oracle Rest Data Services 19c All All All
Application Oracle Siebel Mobile All All All All
Application Oracle Storagetek Acsls 8.5.1 All All All
Application Oracle Storagetek Tape Analytics Sw Tool 2.3.1 All All All
Application Oracle Storagetek Tape Analytics Sw Tool 2.3.1 All All All
Application Oracle Webcenter Sites 12.2.1.3.0 All All All
Application Oracle Webcenter Sites 12.2.1.4.0 All All All
Application Oracle Webcenter Sites 12.2.1.3.0 All All All
Application Oracle Webcenter Sites 12.2.1.4.0 All All All
Application Oracle Weblogic Server 12.1.3.0.0 All All All
Application Oracle Weblogic Server 12.2.1.3.0 All All All
Application Oracle Weblogic Server 12.2.1.4.0 All All All
Application Oracle Weblogic Server 14.1.1.0.0 All All All
Application Oracle Weblogic Server 12.1.3.0.0 All All All
Application Oracle Weblogic Server 12.2.1.3.0 All All All
Application Oracle Weblogic Server 12.2.1.4.0 All All All
Application Oracle Weblogic Server 14.1.1.0.0 All All All
Application Tenable Log Correlation Engine All All All All

References

ReferenceSourceLinkTags
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
[security-announce] openSUSE-SU-2020:1106-1: moderate: Security update f SUSE lists.opensuse.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
[security-announce] openSUSE-SU-2020:1060-1: moderate: Security update f SUSE lists.opensuse.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
[SECURITY] Fedora 33 Update: drupal7-7.72-1.fc33 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
Pony Mail! lists.apache.org
[security-announce] openSUSE-SU-2020:1888-1: moderate: Security update f SUSE lists.opensuse.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Patch, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! lists.apache.org
Pony Mail! lists.apache.org
Oracle Critical Patch Update Advisory - July 2020 MISC www.oracle.com Third Party Advisory
Pony Mail! lists.apache.org
May 2020 jQuery Vulnerabilities in NetApp Products | NetApp Product Security CONFIRM security.netapp.com Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
jQuery Core 3.5 Upgrade Guide | jQuery MISC jquery.com Release Notes, Vendor Advisory
Pony Mail! lists.apache.org
Oracle Critical Patch Update Advisory - April 2022 MISC www.oracle.com
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
[SECURITY] Fedora 31 Update: drupal7-7.72-1.fc31 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! lists.apache.org
[flink-issues] 20211031 [jira] [Updated] (FLINK-20014) Resolve CVE-2020-11022 and CVE-2020-11023 in scala-compiler lists.apache.org
Oracle Critical Patch Update Advisory - October 2020 MISC www.oracle.com Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Oracle Critical Patch Update Advisory - July 2021 N/A www.oracle.com
Pony Mail! MLIST lists.apache.org
[SECURITY] [DLA 2608-1] jquery security update MLIST lists.debian.org
Pony Mail! MLIST lists.apache.org
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2020-002 | Drupal.org CONFIRM www.drupal.org Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! lists.apache.org
[SECURITY] Fedora 31 Update: drupal7-7.72-1.fc31 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
jQuery 1.0.3 Cross Site Scripting ≈ Packet Storm MISC packetstormsecurity.com
Oracle Critical Patch Update Advisory - October 2021 MISC www.oracle.com
Pony Mail! lists.apache.org
[R1] LCE 6.0.9 Fixes Multiple Third-party Vulnerabilities - Security Advisory | Tenable® CONFIRM www.tenable.com
Cacti: Multiple vulnerabilities (GLSA 202007-03) — Gentoo security GENTOO security.gentoo.org Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org
Pony Mail! lists.apache.org
Pony Mail! lists.apache.org
Oracle Critical Patch Update Advisory - January 2022 MISC www.oracle.com
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
[SECURITY] [DLA 3551-1] otrs2 security update MLIST lists.debian.org
Pony Mail! lists.apache.org
jQuery 3.5.0 Released! | Official jQuery Blog MISC blog.jquery.com Release Notes, Vendor Advisory
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
[SECURITY] Fedora 32 Update: drupal7-7.72-1.fc32 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
[SECURITY] Fedora 32 Update: drupal8-8.9.0-1.fc32 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org
[R1] Nessus Network Monitor 5.13.0 Fixes One Third-party Vulnerability - Security Advisory | Tenable® CONFIRM www.tenable.com Third Party Advisory
Pony Mail! lists.apache.org
Debian -- Security Information -- DSA-4693-1 drupal7 DEBIAN www.debian.org Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Patch, Third Party Advisory
[SECURITY] Fedora 33 Update: drupal7-7.72-1.fc33 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
[SECURITY] Fedora 32 Update: drupal8-8.9.0-1.fc32 - package-announce - Fedora Mailing-Lists lists.fedoraproject.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! lists.apache.org
Potential XSS vulnerability when appending HTML containing option elements · Advisory · jquery/jquery · GitHub CONFIRM github.com Third Party Advisory
Oracle Critical Patch Update Advisory - July 2022 N/A www.oracle.com
Oracle Critical Patch Update Advisory - April 2021 MISC www.oracle.com
Pony Mail! lists.apache.org
Pony Mail! MLIST lists.apache.org Mailing List, Third Party Advisory
Pony Mail! MLIST lists.apache.org
Oracle Critical Patch Update Advisory - January 2021 MISC www.oracle.com Third Party Advisory
Pony Mail! lists.apache.org
[SECURITY] Fedora 32 Update: drupal7-7.72-1.fc32 - package-announce - Fedora Mailing-Lists FEDORA lists.fedoraproject.org Mailing List, Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
CISA Known Exploited Vulnerabilities catalog CISA www.cisa.gov kev

Legacy QID Mappings

  • 10083 Atlassian Jira Cross-Site Scripting Vulnerability(JRASERVER-72052)
  • 14011 Ansible Tower Security Update 3.8.2 Multiple Vulnerabilities
  • 159121 Oracle Enterprise Linux Security Update for ipa (ELSA-2021-0860)
  • 159337 Oracle Enterprise Linux Security Update for bootstrap (ELSA-2021-9400)
  • 159459 Oracle Enterprise Linux Security Update for idm:DL1 and idm:client (ELSA-2021-1846)
  • 159559 Oracle Enterprise Linux Security Update for pcs (ELSA-2021-9552)
  • 159661 Oracle Enterprise Linux Security Update for jquery-ui (ELSA-2022-9177)
  • 159679 Oracle Enterprise Linux Security Update for pki-core:10.6 and pki-deps:10.6 (ELSA-2020-4847)
  • 178505 Debian Security Update for jquery (DLA 2608-1)
  • 20215 Oracle Database 19c Critical Patch Update - April 2021
  • 20216 Oracle Database 18c Critical Patch Update - April 2021
  • 20217 Oracle Database 12.2.0.1 Critical Patch Update - April 2021
  • 20218 Oracle Database 12.2.0.1 Critical Patch Update - April 2021 (Unauthenticated)
  • 20219 Oracle Database 12.1.0.2 Critical Patch Update - April 2021
  • 20220 Oracle Database 12.1.0.2 Critical Patch Update - April 2021 (Unauthenticated)
  • 20288 Oracle Database 19c Critical OJVM Patch Update - October 2020
  • 20297 Oracle Database 18c Critical OJVM Patch Update - October 2020
  • 20313 Oracle Database 12.2.0.1 Critical OJVM Patch Update - October 2020
  • 239175 Red Hat Update for ipa (RHSA-2021:0860)
  • 239296 Red Hat Update for idm:DL1 and idm:client (RHSA-2021:1846)
  • 239838 Red Hat Update for pcs security (RHSA-2021:4142)
  • 241153 Red Hat Update for JBoss Enterprise Application Platform 7.4.9 (RHSA-2023:0554)
  • 241154 Red Hat Update for JBoss Enterprise Application Platform 7.4.9 (RHSA-2023:0552)
  • 241155 Red Hat Update for JBoss Enterprise Application Platform 7.4.9 (RHSA-2023:0553)
  • 296073 Oracle Solaris 11.4 Support Repository Update (SRU) 24.75.2 Missing (CPUJUL2020)
  • 352271 Amazon Linux Security Advisory for ipa: ALAS2-2021-1626
  • 375630 HPE System Management Homepage Cross Site Scripting Vulnerabilitiy
  • 377491 Alibaba Cloud Linux Security Update for ipa (ALINUX2-SA-2021:0015)
  • 377817 Alibaba Cloud Linux Security Update for pcs (ALINUX2-SA-2022:0056)
  • 500875 Alpine Linux Security Update for drupal7
  • 501529 Alpine Linux Security Update for cacti
  • 504593 Alpine Linux Security Update for cacti
  • 504699 Alpine Linux Security Update for drupal7
  • 590764 Mitsubishi Electric EcoWebServerIII Multiple Vulnerabilities (ICSA-22-055-02)
  • 590808 Mitsubishi Electric EcoWebServerIII Multiple Vulnerabilities (ICSA-22-055-02)
  • 6000085 Debian Security Update for otrs2 (DLA 3551-1)
  • 690483 Free Berkeley Software Distribution (FreeBSD) Security Update for cacti (cd2dc126-cfe4-11ea-9172-4c72b94353b5)
  • 940114 AlmaLinux Security Update for pcs (ALSA-2021:4142)
  • 940348 AlmaLinux Security Update for pki-core:10.6 and pki-deps:10.6 (ALSA-2020:4847)
  • 940379 AlmaLinux Security Update for idm:DL1 and idm:client (ALSA-2021:1846)
  • 960454 Rocky Linux Security Update for pki-core:10.6 and pki-deps:10.6 (RLSA-2020:4847)
  • 960462 Rocky Linux Security Update for idm:DL1 and idm:client (RLSA-2021:1846)
  • 960746 Rocky Linux Security Update for pcs (RLSA-2021:4142)
  • 980084 Nodejs (npm) Security Update for jquery (GHSA-jpcq-cgw6-v4j6)
  • 995465 Java (Maven) Security Update for org.webjars.npm:jquery (GHSA-jpcq-cgw6-v4j6)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report