CVE-2020-23064

Cross Site Scripting vulnerability in jQuery 2.2.0 through 3.x before 3.5.0 allows a remote attacker to execute arbitrary code via the <options> element.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:brocade_san_navigator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:virtual_desktop_service:-:*:*:*:*:*:*:*

History

01 Apr 2024, 15:43

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20230725-0003/ - () https://security.netapp.com/advisory/ntap-20230725-0003/ - Third Party Advisory
First Time Netapp management Services For Element Software And Netapp Hci
Netapp
Netapp cloud Backup
Netapp virtual Desktop Service
Netapp active Iq Unified Manager
Netapp brocade San Navigator
CPE cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:brocade_san_navigator:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:virtual_desktop_service:-:*:*:*:*:*:*:*

25 Jul 2023, 15:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230725-0003/ -

04 Jul 2023, 01:38

Type Values Removed Values Added
CWE CWE-79
CPE cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*
References (MISC) https://snyk.io/vuln/SNYK-JS-JQUERY-565129 - (MISC) https://snyk.io/vuln/SNYK-JS-JQUERY-565129 - Third Party Advisory
References (MISC) https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ - (MISC) https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ - Release Notes
First Time Jquery
Jquery jquery
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

27 Jun 2023, 13:15

Type Values Removed Values Added
Summary Cross Site Scripting vulnerability in jQuery v.2.2.0 thru v.3.5.0 allows a remote attacker to execute arbitrary code via the <options> element. Cross Site Scripting vulnerability in jQuery 2.2.0 through 3.x before 3.5.0 allows a remote attacker to execute arbitrary code via the <options> element.

26 Jun 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-26 19:15

Updated : 2024-04-01 15:43


NVD link : CVE-2020-23064

Mitre link : CVE-2020-23064

CVE.ORG link : CVE-2020-23064


JSON object : View

Products Affected

jquery

  • jquery

netapp

  • brocade_san_navigator
  • active_iq_unified_manager
  • virtual_desktop_service
  • management_services_for_element_software_and_netapp_hci
  • cloud_backup
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')