CVE-2020-11022: Debian Linux
Medium severity, CVSS 6.1. EPSS: 99.2% chance of exploitation in the next 30 days.
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Affected products
- Debian Debian Linux: version 9.0 only
- Drupal Drupal: from 7.0, before 7.70 (fixed in 7.70); from 8.7.0, before 8.7.14 (fixed in 8.7.14); from 8.8.0, before 8.8.6 (fixed in 8.8.6)
- Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
- jQuery jQuery: from 1.2, before 3.5.0 (fixed in 3.5.0)
- Netapp h300e Firmware: affected versions not specified
- Netapp h300s Firmware: affected versions not specified
- Netapp h410c Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500e Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h700e Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
- Netapp Max Data: affected versions not specified
- Netapp Oncommand Insight: affected versions not specified
- Netapp Oncommand System Manager: from 3.0, up to and including 3.1.3
- Netapp Snap Creator Framework: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Opensuse Leap: version 15.1 only; version 15.2 only
- Oracle Agile Product Lifecycle Management For Process: version 6.2.0.0 only
- Oracle Agile Product Supplier Collaboration For Process: version 6.2.0.0 only
- Oracle Application Testing Suite: version 13.3.0.1 only
- Oracle Banking Digital Experience: version 18.1 only; version 18.2 only; version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only; …
- Oracle Blockchain Platform: before 21.1.2 (fixed in 21.1.2)
- Oracle Communications Application Session Controller: version 3.8m0 only
- Oracle Communications Billing And Revenue Management: version 7.5.0.23.0 only; version 12.0.0.3.0 only
- and 45 more
Published 2020-04-29. Last modified 2026-06-17.