---
cve: "CVE-2020-11023"
severity: "MEDIUM"
cvss: 6.9
epss: "83.8%"
vendor: "jquery"
kev: true
exploited: true
published: "2020-04-29 21:15:11"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T22:47:13+02:00"
---

# CVE-2020-11023

> 6.9 MEDIUM · ⚠️ CISA KEV (593 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing  elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Exploit-Evidenz

- [EDB-49767 — jQuery 1.0.3 - Cross-Site Scripting (XSS)](https://www.exploit-db.com/exploits/49767)

## Patch verfügbar (OSV)

- c62d5ba13e02923cf4f6e2a7ede0d2afcaa68043 (Commit)
- ee0693f6d6bdc5cd772e163e6ed410567d82d33f (Commit)

## Referenzen

- <https://www.debian.org/security/2020/dsa-4693>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K/>
- <https://www.oracle.com/security-alerts/cpujul2020.html>
- <https://jquery.com/upgrade-guide/3.5/>
- <https://security.netapp.com/advisory/ntap-20200511-0006/>
- <https://www.drupal.org/sa-core-2020-002>
- <https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6>
- <https://blog.jquery.com/2020/04/10/jquery-3-5-0-released>
- <http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html>
- <https://security.gentoo.org/glsa/202007-03>
- <http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html>
- <https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec%40%3Cissues.hive.apache.org%3E>
- <https://lists.apache.org/thread.html/rf661a90a15da8da5922ba6127b3f5f8194d4ebec8855d60a0dd13248%40%3Cdev.hive.apache.org%3E>
- <https://lists.apache.org/thread.html/r9c5fda81e4bca8daee305b4c03283dddb383ab8428a151d4cb0b3b15%40%3Cissues.hive.apache.org%3E>
- <https://lists.apache.org/thread.html/ra3c9219fcb0b289e18e9ec5a5ebeaa5c17d6b79a201667675af6721c%40%3Cgitbox.hive.apache.org%3E>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-11023) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
