CVE-2020-7656
Summary
| CVE | CVE-2020-7656 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-19 21:15:00 UTC |
| Updated | 2023-06-22 19:49:00 UTC |
| Description | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Cross-site Scripting (XSS) in jquery | Snyk |
MISC |
snyk.io |
Exploit, Third Party Advisory |
| CEC Juniper Community |
MISC |
supportportal.juniper.net |
|
| CVE-2020-7656 jQuery Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159559 Oracle Enterprise Linux Security Update for pcs (ELSA-2021-9552)
- 239838 Red Hat Update for pcs security (RHSA-2021:4142)
- 730499 jQuery Prior to 1.9.0 Cross-Site Scripting Vulnerability
- 940114 AlmaLinux Security Update for pcs (ALSA-2021:4142)
- 960746 Rocky Linux Security Update for pcs (RLSA-2021:4142)
- 981486 Nodejs (npm) Security Update for jquery (GHSA-q4m3-2j7h-f7xw)
- 995794 Java (Maven) Security Update for org.webjars.npm:jquery (GHSA-q4m3-2j7h-f7xw)