Skip to content

CVE-2020-11023 @ Npm-jquery-3.2.1 #15998

@cx-nitzan-massader

Description

@cx-nitzan-massader

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2020-11023
Checkmarx Project: AsafOrgTesting/Sast-Sca-Test-Repo
Repository URL: https://github.com/AsafOrgTesting/Sast-Sca-Test-Repo
Branch: master
Scan ID: 381445f1-c79b-4b6f-9733-56cc146401f9


In jQuery versions 1.0.3 through 3.4.1, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This vulnerability also affects jquery-rails versions through 4.3.5.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: 3.5.0

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions