EXPOSURES › CVE-2020-11023
CVE-2020-11023
HIGH ⌖ ON CISA KEV · EXPLOITEDJQuery's DOM manipulators execute untrusted code when processing malicious HTML input, enabling XSS attacks.
JQuery's DOM manipulation functions allow execution of untrusted code when processing malicious HTML input, creating a persistent XSS vulnerability that can compromise browser contexts. DIB organizations must audit all JQuery usage in FedRAMP systems and apply vendor patches immediately to prevent credential theft or session hijacking.
Shame score — A known XSS vulnerability in a widely-used library that requires vendor patching rather than representing a supply-chain default credential failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.