QID 352271

Date Published: 2021-04-26

QID 352271: Amazon Linux Security Advisory for ipa: ALAS2-2021-1626

<DIV ID="issue_overview">
A flaw was found in jQuery. HTML containing <OPTION> elements from untrusted sources are passed, even after sanitizing, to one of jQuery's DOM manipulation methods, which may execute untrusted code. The highest threat from this vulnerability is to data confidentiality and integrity. (CVE-2020-11023 )</OPTION>
</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Please refer to Amazon advisory: ALAS-2021-1626 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352271

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1626 Amazon Linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1626.html