---
title: "CVE-2020-11023"
canonical: "https://kb.cynergy.app/space/MD/899219880/CVE-2020-11023"
format: markdown
---
**Description:**

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

**Published On:**

2020-04-29

**Updated On:**

2022-05-12

**Trending:**

FALSE

**CWE:**

CWE-79

**Mitigation:**

![image](media://f7e970d4-7033-42f3-bbd2-420a459d6bad)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| HSMH-210715 | microsoft | cp047446_7.6.7.2n.exe | Upgrade Requirement:<br>Critical - HPE requires users update to this version immediately.<br>Updated jquery to version 3.6.0(CVE-2020-11022 & CVE-2020-11023) | 2021-12-19 | [https://support.hpe.com/hpesc/public/swd/detail?swItemId=MTX_75b6e680523d44768075ab77d1#tab3](https://support.hpe.com/hpesc/public/swd/detail?swItemId=MTX_75b6e680523d44768075ab77d1#tab3) |
| HSMH-210715 | hp | cp047446_7.6.7.2.exe | Upgrade Requirement:<br>Critical - HPE requires users update to this version immediately.<br>Updated jquery to version 3.6.0(CVE-2020-11022 & CVE-2020-11023) | 2021-12-19 | [https://support.hpe.com/hpesc/public/swd/detail?swItemId=MTX_75b6e680523d44768075ab77d1#tab3](https://support.hpe.com/hpesc/public/swd/detail?swItemId=MTX_75b6e680523d44768075ab77d1#tab3) |
| RHSA-2020:4847 | apache | jss-4.7.3-1.module+el8.3.0+8058+d5cd4219 | An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:4847](https://access.redhat.com/errata/RHSA-2020:4847) |
| RHSA-2021:0860 | OpenSource | ipa-4.6.8-5.el7_9.4 | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2021:0860](https://access.redhat.com/errata/RHSA-2021:0860) |
| RHSA-2021:1846 | OpenSource | ipa-4.9.2-3.module+el8.4.0+10413+a92f1bfa | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2021:1846](https://access.redhat.com/errata/RHSA-2021:1846) |
| openSUSE-SU-2020:1060-1 | suse | Security update for cacti, cacti-spine | This update for cacti, cacti-spine fixes the following issues:<br>- cacti 1.2.13:<br>- Query XSS vulnerabilities require vendor package update<br>(CVE-2020-11022 / CVE-2020-11023)<br>- Lack of escaping on some pages can lead to XSS exposure
- Update PHPMailer to 6.1.6 (CVE-2020-13625)
- SQL Injection vulnerability due to input validation failure when<br>editing colors (CVE-2020-14295, boo#1173090)<br>- Lack of escaping on template import can lead to XSS exposure<br>- switch from cron to systemd timers (boo#1115436):<br>+ cacti-cron.timer  
  + cacti-cron.service<br>- avoid potential root escalation on systems with fs.protected_hardlinks=0<br>(boo#1154087): handle directory permissions in file section instead  
  of using chown during post installation<br>- rewrote apache configuration to get rid of .htaccess files and<br>explicitely disable directory permissions per default   
  (only allow a limited, well-known set of directories) | 2020-07-28 | [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html) |
| RHSA-2020:2412 | redhat | Red Hat Security Advisory: OpenShift Container Platform 4.5 container image security update | An update is now available for Red Hat OpenShift Container Platform 4.5.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-07-14 | [https://access.redhat.com/errata/RHSA-2020:2412](https://access.redhat.com/errata/RHSA-2020:2412) |
| RHSA-2020:3247 | redhat | Red Hat Security Advisory: RHV Manager (ovirt-engine) 4.4 security, bug fix, and enhancement update | Updated ovirt-engine packages that fix several bugs and add various enhancements are now available.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-08-05 | [https://access.redhat.com/errata/RHSA-2020:3247](https://access.redhat.com/errata/RHSA-2020:3247) |
| RHSA-2020:3369 | redhat | Red Hat Security Advisory: Red Hat OpenShift Service Mesh security update | An update is now available for OpenShift Service Mesh 1.1.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-08-07 | [https://access.redhat.com/errata/RHSA-2020:3369](https://access.redhat.com/errata/RHSA-2020:3369) |
| RHSA-2020:3807 | redhat | Red Hat Security Advisory: Red Hat Virtualization security, bug fix, and enhancement update | An update is now available for Red Hat Virtualization Engine 4.4.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-09-24 | [https://access.redhat.com/errata/RHSA-2020:3807](https://access.redhat.com/errata/RHSA-2020:3807) |
| RHSA-2020:4211 | redhat | Red Hat Security Advisory: Red Hat AMQ Interconnect 1.9.0 release and security update | Red Hat AMQ Interconnect 1.9.0 release packages are available for A-MQ Interconnect on RHEL 6, 7, and 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-10 | [https://access.redhat.com/errata/RHSA-2020:4211](https://access.redhat.com/errata/RHSA-2020:4211) |
| RHSA-2020:4298 | redhat | Red Hat Security Advisory: OpenShift Container Platform 4.6.1 image security update | An update is now available for Red Hat OpenShift Container Platform 4.6.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-29 | [https://access.redhat.com/errata/RHSA-2020:4298](https://access.redhat.com/errata/RHSA-2020:4298) |
| RHSA-2020:4847 | redhat | Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update | An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-11-05 | [https://access.redhat.com/errata/RHSA-2020:4847](https://access.redhat.com/errata/RHSA-2020:4847) |
| RHSA-2020:5249 | redhat | Red Hat Security Advisory: security update - Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container | Red Hat Ansible Tower 3.7.4-1 - RHEL7 Container | 2020-12-01 | [https://access.redhat.com/errata/RHSA-2020:5249](https://access.redhat.com/errata/RHSA-2020:5249) |
| RHSA-2020:5412 | redhat | Red Hat Security Advisory: python-XStatic-jQuery224 security update | An update for python-XStatic-jQuery224 is now available for Red Hat  
OpenStack Platform 16.1 (Train).<br>Red Hat Product Security has rated this update as having a security impact  
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which  
gives a detailed severity rating, is available for each vulnerability from  
the CVE link(s) in the References section. | 2020-12-19 | [https://access.redhat.com/errata/RHSA-2020:5412](https://access.redhat.com/errata/RHSA-2020:5412) |
| RHSA-2021:0778 | redhat | Red Hat Security Advisory: Red Hat Ansible Tower 3.6.7-1 - Container security and bug fix update | Red Hat Ansible Tower 3.6.7-1 - RHEL7 Container<br>Red Hat Product Security has rated this update as having a security impact of  
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-03-10 | [https://access.redhat.com/errata/RHSA-2021:0778](https://access.redhat.com/errata/RHSA-2021:0778) |
| RHSA-2021:0860 | redhat | Red Hat Security Advisory: ipa security and bug fix update | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-03-18 | [https://access.redhat.com/errata/RHSA-2021:0860](https://access.redhat.com/errata/RHSA-2021:0860) |
| RHSA-2021:1846 | redhat | Red Hat Security Advisory: idm:DL1 and idm:client security, bug fix, and enhancement update | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-05-20 | [https://access.redhat.com/errata/RHSA-2021:1846](https://access.redhat.com/errata/RHSA-2021:1846) |
| RHSA-2021:4142 | redhat | Red Hat Security Advisory: pcs security, bug fix, and enhancement update | An update for pcs is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-11-11 | [https://access.redhat.com/errata/RHSA-2021:4142](https://access.redhat.com/errata/RHSA-2021:4142) |
| FEDORA-2020-0b32a59b54 | fedora | Fedora 32 Update: drupal7-7.72-1.fc32 | - [https://www.drupal.org/project/drupal/releases/7.72](https://www.drupal.org/project/drupal/releases/7.72)      - [Drupal core -<br>Critical - Cross Site Request Forgery - SA-  
CORE-2020-004]([https://www.drupal.org/sa-core-2020-004](https://www.drupal.org/sa-core-2020-004) ) / CVE-2020-13663 -  
[https://www.drupal.org/project/drupal/releases/7.71](https://www.drupal.org/project/drupal/releases/7.71)  -  
[https://www.drupal.org/project/drupal/releases/7.70](https://www.drupal.org/project/drupal/releases/7.70)      - [Drupal core -  
Moderately critical - Cross Site Scripting - SA-  
CORE-2020-002]([https://www.drupal.org/sa-core-2020-002](https://www.drupal.org/sa-core-2020-002) ) / CVE-2020-11022 /  
CVE-2020-11023     - [Drupal core - Moderately critical - Open Redirect - SA-  
CORE-2020-003]([https://www.drupal.org/sa-core-2020-003](https://www.drupal.org/sa-core-2020-003) ) / CVE-2020-13662 | 2020-09-14 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-0b32a59b54](https://bodhi.fedoraproject.org/updates/FEDORA-2020-0b32a59b54) |
| FEDORA-2020-36d2db5f51 | fedora | Fedora 32 Update: drupal8-8.9.0-1.fc32 | - [https://www.drupal.org/project/drupal/releases/8.9.0](https://www.drupal.org/project/drupal/releases/8.9.0)  -<br>[https://www.drupal.org/project/drupal/releases/8.8.7](https://www.drupal.org/project/drupal/releases/8.8.7)  -  
[https://www.drupal.org/project/drupal/releases/8.8.6](https://www.drupal.org/project/drupal/releases/8.8.6)      - [SA-  
CORE-2020-002]([https://www.drupal.org/sa-core-2020-002](https://www.drupal.org/sa-core-2020-002) ) /  
[CVE-2020-11022]([https://nvd.nist.gov/vuln/detail/CVE-2020-11022](https://nvd.nist.gov/vuln/detail/CVE-2020-11022) ) /  
[CVE-2020-11023]([https://nvd.nist.gov/vuln/detail/CVE-2020-11023](https://nvd.nist.gov/vuln/detail/CVE-2020-11023) ) -  
[https://www.drupal.org/project/drupal/releases/8.8.5](https://www.drupal.org/project/drupal/releases/8.8.5) | 2020-06-16 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-36d2db5f51](https://bodhi.fedoraproject.org/updates/FEDORA-2020-36d2db5f51) |
| FEDORA-2020-fbb94073a1 | fedora | Fedora 31 Update: drupal7-7.72-1.fc31 | - [https://www.drupal.org/project/drupal/releases/7.72](https://www.drupal.org/project/drupal/releases/7.72)      - [Drupal core -<br>Critical - Cross Site Request Forgery - SA-  
CORE-2020-004]([https://www.drupal.org/sa-core-2020-004](https://www.drupal.org/sa-core-2020-004) ) / CVE-2020-13663 -  
[https://www.drupal.org/project/drupal/releases/7.71](https://www.drupal.org/project/drupal/releases/7.71)  -  
[https://www.drupal.org/project/drupal/releases/7.70](https://www.drupal.org/project/drupal/releases/7.70)      - [Drupal core -  
Moderately critical - Cross Site Scripting - SA-  
CORE-2020-002]([https://www.drupal.org/sa-core-2020-002](https://www.drupal.org/sa-core-2020-002) ) / CVE-2020-11022 /  
CVE-2020-11023     - [Drupal core - Moderately critical - Open Redirect - SA-  
CORE-2020-003]([https://www.drupal.org/sa-core-2020-003](https://www.drupal.org/sa-core-2020-003) ) / CVE-2020-13662 | 2020-09-14 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-fbb94073a1](https://bodhi.fedoraproject.org/updates/FEDORA-2020-fbb94073a1) |
| FEDORA-2020-fe94df8c34 | fedora | Fedora 33 Update: drupal7-7.72-1.fc33 | - [https://www.drupal.org/project/drupal/releases/7.72](https://www.drupal.org/project/drupal/releases/7.72)      - [Drupal core -<br>Critical - Cross Site Request Forgery - SA-  
CORE-2020-004]([https://www.drupal.org/sa-core-2020-004](https://www.drupal.org/sa-core-2020-004) ) / CVE-2020-13663 -  
[https://www.drupal.org/project/drupal/releases/7.71](https://www.drupal.org/project/drupal/releases/7.71) | 2020-10-10 | [https://bodhi.fedoraproject.org/updates/FEDORA-2020-fe94df8c34](https://bodhi.fedoraproject.org/updates/FEDORA-2020-fe94df8c34) |
| openSUSE-SU-2020:1060-1 | suse | Security update for cacti, cacti-spine | This update for cacti, cacti-spine fixes the following issues:<br>- cacti 1.2.13:<br>- Query XSS vulnerabilities require vendor package update<br>(CVE-2020-11022 / CVE-2020-11023)<br>- Lack of escaping on some pages can lead to XSS exposure
- Update PHPMailer to 6.1.6 (CVE-2020-13625)
- SQL Injection vulnerability due to input validation failure when<br>editing colors (CVE-2020-14295, boo#1173090)<br>- Lack of escaping on template import can lead to XSS exposure<br>- switch from cron to systemd timers (boo#1115436):<br>+ cacti-cron.timer  
  + cacti-cron.service<br>- avoid potential root escalation on systems with fs.protected_hardlinks=0<br>(boo#1154087): handle directory permissions in file section instead  
  of using chown during post installation<br>- rewrote apache configuration to get rid of .htaccess files and<br>explicitely disable directory permissions per default   
  (only allow a limited, well-known set of directories) | 2021-04-17 | [https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html](https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html) |
| openSUSE-SU-2020:1106-1 | suse | Security update for cacti, cacti-spine | This update for cacti, cacti-spine fixes the following issues:<br>- cacti 1.2.13:<br>- Query XSS vulnerabilities require vendor package update<br>(CVE-2020-11022 / CVE-2020-11023)<br>- Lack of escaping on some pages can lead to XSS exposure
- Update PHPMailer to 6.1.6 (CVE-2020-13625)
- SQL Injection vulnerability due to input validation failure when<br>editing colors (CVE-2020-14295, boo#1173090)<br>- Lack of escaping on template import can lead to XSS exposure<br>- switch from cron to systemd timers (boo#1115436):<br>+ cacti-cron.timer  
  + cacti-cron.service<br>- avoid potential root escalation on systems with fs.protected_hardlinks=0<br>(boo#1154087): handle directory permissions in file section instead  
  of using chown during post installation<br>- rewrote apache configuration to get rid of .htaccess files and<br>explicitely disable directory permissions per default   
  (only allow a limited, well-known set of directories)<br>This update was imported from the openSUSE:Leap:15.1:Update update project. | 2022-03-25 | [https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html](https://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html) |
| openSUSE-SU-2020:1888-1 | suse | Security update for otrs | This update for otrs fixes the following issues:<br>- otrs was updated to 6.0.30 (OSA-2020-14 boo#1178434)
- CVE-2020-11022, CVE-2020-11023: Vulnerability in third-party library - jquery<br>OTRS uses jquery version 3.4.1, which is vulnerable to cross-site scripting   
    (XSS). | 2021-03-26 | [https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html](https://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html) |
| glsa202007-03 | gentoo | Cacti: Multiple vulnerabilities | <p>Multiple vulnerabilities have been discovered in Cacti. Please review  
      the CVE identifiers referenced below for details.  
    </p> | 2020-07-29 | [https://security.gentoo.org/glsa/202007-03](https://security.gentoo.org/glsa/202007-03) |
| CPUApr2021 | oracle | Oracle Critical Patch Update Advisory - April 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-05-06 | [https://www.oracle.com/security-alerts/cpuapr2021.html](https://www.oracle.com/security-alerts/cpuapr2021.html) |
| CPUJan2022 | oracle | Oracle Critical Patch Update Advisory - January 2022 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2022-03-25 | [https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html) |
| CPUJul2021 | oracle | Oracle Critical Patch Update Advisory - July 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-08-25 | [https://www.oracle.com/security-alerts/cpujul2021.html](https://www.oracle.com/security-alerts/cpujul2021.html) |
| CPUOct2020 | oracle | Oracle Critical Patch Update Advisory - October 2020 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2020-11-06 | [https://www.oracle.com/security-alerts/cpuoct2020.html](https://www.oracle.com/security-alerts/cpuoct2020.html) |
| CPUOct2021 | oracle | Oracle Critical Patch Update Advisory - October 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-11-06 | [https://www.oracle.com/security-alerts/cpuoct2021.html](https://www.oracle.com/security-alerts/cpuoct2021.html) |