CVE-2020-11023
JQuery Cross-Site Scripting (XSS) Vulnerability
Description
CVE-2020-11023 is a medium-severity cross-site scripting (XSS) vulnerability in jQuery versions 1.0.3 through 3.4.x that allows attackers to execute arbitrary JavaScript in the context of a victim's browser session. With a CVSS v3.1 base score of 6.9, the flaw exists in jQuery's DOM manipulation methods (.html(), .append(), and others) where passing HTML containing
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:NOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| jquery | jquery | >= 1.0.3, < 3.5.0 |
| debian | debian linux | 9.0 |
| fedoraproject | fedora | 31; 32; 33 |
| drupal | drupal | >= 7.0, < 7.70; >= 8.7.0, < 8.7.14; >= 8.8.0, < 8.8.6 |
| oracle | application express | < 20.2 |
| oracle | application testing suite | 13.3.0.1 |
| oracle | banking enterprise collections | >= 2.7.0, <= 2.8.0 |
| oracle | banking platform | >= 2.4.0, <= 2.10.0 |
| oracle | blockchain platform | < 21.1.2; 21.1.2 |
| oracle | business intelligence | 5.9.0.0.0 |
| oracle | communications analytics | 12.1.1 |
| oracle | communications eagle application processor | >= 16.1.0, <= 16.4.0 |
| oracle | communications element manager | 8.1.1; 8.2.0; 8.2.1 |
| oracle | communications interactive session recorder | >= 6.1, <= 6.4 |
| oracle | communications operations monitor | >= 4.1, <= 4.3; 3.4 |
| oracle | communications services gatekeeper | 7.0 |
| oracle | communications session report manager | 8.1.1; 8.2.0; 8.2.1 |
| oracle | communications session route manager | 8.1.1; 8.2.0; 8.2.1 |
| oracle | financial services regulatory reporting for de nederlandsche bank | 8.0.4 |
| oracle | financial services revenue management and billing analytics | 2.7; 2.8 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00067.html(Broken Link)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00085.html(Broken Link)
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00039.html(Broken Link, Mailing List, Third Party Advisory)
- http://packetstormsecurity.com/files/162160/jQuery-1.0.3-Cross-Site-Scripting.html(Exploit, Third Party Advisory, VDB Entry)
- https://blog.jquery.com/2020/04/10/jquery-3-5-0-released(Release Notes, Vendor Advisory)
- https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6(Third Party Advisory)
- https://jquery.com/upgrade-guide/3.5/(Release Notes, Vendor Advisory)
- https://lists.apache.org/thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r0593393ca1e97b1e7e098fe69d414d6bd0a467148e9138d07e86ebbb%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r07ab379471fb15644bf7a92e4a98cbc7df3cf4e736abae0cc7625fe6%40%3Cdev.felix.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r094f435595582f6b5b24b66fedf80543aa8b1d57a3688fbcc21f06ec%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r1fed19c860a0d470f2a3eded12795772c8651ff583ef951ddac4918c%40%3Cgitbox.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r2c85121a47442036c7f8353a3724aa04f8ecdfda1819d311ba4f5330%40%3Cdev.felix.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r3702ede0ff83a29ba3eb418f6f11c473d6e3736baba981a8dbd9c9ef%40%3Cdev.felix.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r4aadb98086ca72ed75391f54167522d91489a0d0ae25b12baa8fc7c5%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r4dba67be3239b34861f1b9cfdf9dfb3a90272585dcce374112ed6e16%40%3Cdev.felix.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r55f5e066cc7301e3630ce90bbbf8d28c82212ae1f2d4871012141494%40%3Cdev.felix.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r6c4df3b33e625a44471009a172dabe6865faec8d8f21cac2303463b1%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r6e97b37963926f6059ecc1e417721608723a807a76af41d4e9dbed49%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r9006ad2abf81d02a0ef2126bab5177987e59095b7194a487c4ea247c%40%3Ccommits.felix.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r9c5fda81e4bca8daee305b4c03283dddb383ab8428a151d4cb0b3b15%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/r9e0bd31b7da9e7403478d22652b8760c946861f8ebd7bd750844898e%40%3Cdev.felix.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/ra32c7103ded9041c7c1cb8c12c8d125a6b2f3f3270e2937ef8417fac%40%3Cgitbox.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/ra374bb0299b4aa3e04edde01ebc03ed6f90cf614dad40dd428ce8f72%40%3Cgitbox.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/ra3c9219fcb0b289e18e9ec5a5ebeaa5c17d6b79a201667675af6721c%40%3Cgitbox.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/ra406b3adfcffcb5ce8707013bdb7c35e3ffc2776a8a99022f15274c6%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rab82dd040f302018c85bd07d33f5604113573514895ada523c3401d9%40%3Ccommits.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/radcb2aa874a79647789f3563fcbbceaf1045a029ee8806b59812a8ea%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rb25c3bc7418ae75cba07988dafe1b6912f76a9dd7d94757878320d61%40%3Cgitbox.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rb69b7d8217c1a6a2100247a5d06ce610836b31e3f5d73fc113ded8e7%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67%40%3Cdev.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rd38b4185a797b324c8dd940d9213cf99fcdc2dbf1fc5a63ba7dee8c9%40%3Cissues.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679%40%3Ccommits.nifi.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2%40%3Cissues.flink.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rf0f8939596081d84be1ae6a91d6248b96a02d8388898c372ac807817%40%3Cdev.felix.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rf1ba79e564fe7efc56aef7c986106f1cf67a3427d08e997e088e7a93%40%3Cgitbox.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.apache.org/thread.html/rf661a90a15da8da5922ba6127b3f5f8194d4ebec8855d60a0dd13248%40%3Cdev.hive.apache.org%3E(Issue Tracking, Mailing List)
- https://lists.debian.org/debian-lts-announce/2021/03/msg00033.html(Mailing List, Third Party Advisory)
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html(Mailing List, Third Party Advisory)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY/(Mailing List, Third Party Advisory)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K/(Mailing List, Third Party Advisory)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4/(Mailing List, Third Party Advisory)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B/(Mailing List, Third Party Advisory)
- https://security.gentoo.org/glsa/202007-03(Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20200511-0006/(Third Party Advisory)
- https://www.debian.org/security/2020/dsa-4693(Mailing List, Third Party Advisory)
- https://www.drupal.org/sa-core-2020-002(Third Party Advisory)
- https://www.oracle.com//security-alerts/cpujul2021.html(Patch, Third Party Advisory)
- https://www.oracle.com/security-alerts/cpuApr2021.html(Patch, Third Party Advisory)
- https://www.oracle.com/security-alerts/cpuapr2022.html(Patch, Third Party Advisory)
- https://www.oracle.com/security-alerts/cpujan2021.html(Third Party Advisory)
- https://www.oracle.com/security-alerts/cpujan2022.html(Patch, Third Party Advisory)
- https://www.oracle.com/security-alerts/cpujul2020.html(Third Party Advisory)
- https://www.oracle.com/security-alerts/cpujul2022.html(Third Party Advisory)
- https://www.oracle.com/security-alerts/cpuoct2020.html(Third Party Advisory)
- https://www.oracle.com/security-alerts/cpuoct2021.html(Patch, Third Party Advisory)
- https://www.tenable.com/security/tns-2021-02(Third Party Advisory)
- https://www.tenable.com/security/tns-2021-10(Third Party Advisory)
- https://github.com/github/advisory-database/blob/99afa6fdeaf5d1d23e1021ff915a5e5dbc82c1f1/advisories/github-reviewed/2020/04/GHSA-jpcq-cgw6-v4j6/GHSA-jpcq-cgw6-v4j6.json#L20-L37(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11023(US Government Resource)
Weakness Type
Unknown CWE
CVE-2020-11023 does not have a specific CWE assigned in the NVD database, but the vulnerability is a cross-site scripting (XSS) flaw rooted in improper handling of HTML content within jQuery's DOM manipulation methods. When untrusted HTML containing
Impact Analysis
The impact of CVE-2020-11023 primarily affects confidentiality with a high rating, and includes a low integrity impact, while availability is not directly affected. Confidentiality is significantly compromised because successful XSS exploitation allows attackers to steal session cookies, authentication tokens, and other sensitive data from the victim's browser. The changed scope (S:C) in the CVSS vector means the XSS payload executes in the victim's browser context, potentially accessing data from the vulnerable web application and any other applications sharing the same origin.
Integrity receives a low impact rating because while the attacker can modify page content and inject malicious elements visible to the user, the modification is limited to the client side and does not directly alter server-side data. However, the attacker can use the XSS to perform actions on behalf of the victim, submit forms, and trigger state-changing operations that indirectly affect data integrity.
The true severity of CVE-2020-11023 lies in the extraordinary scope of affected systems. jQuery is the most widely deployed JavaScript library in web history, and the vulnerability spans versions from 1.0.3 through 3.4.x — covering nearly two decades of releases. The EPSS score of 36.28% at the 97.0th percentile confirms massive exploitation activity. The affected ecosystem extends far beyond jQuery itself: Drupal versions 7 through 8.8.6 are affected, along with dozens of Oracle products including database management tools, middleware, and enterprise applications. Debian, Fedora, and other Linux distributions have issued advisories. A public exploit is available on Packet Storm Security, further lowering the exploitation barrier.
Exploit Maturity
CVE-2020-11023 demonstrates high exploit maturity with public exploit code available and active exploitation confirmed through its inclusion in CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of February 13, 2025. The EPSS score of 36.28% at the 97.0th percentile reflects pervasive exploitation activity. A public exploit is available at Packet Storm Security, and the jQuery team has published detailed information in their security advisory (GHSA-jpcq-cgw6-v4j6).
The vulnerability's inclusion in the KEV catalog in 2025, five years after disclosure, underscores the persistent challenge of updating jQuery across the millions of websites and applications that depend on it. Many legacy applications, content management systems, and enterprise platforms still ship with vulnerable jQuery versions. The fix was introduced in jQuery 3.5.0, and the upgrade guide documents the changes. Major platforms including Drupal issued emergency updates (SA-CORE-2020-002), and Oracle has addressed the vulnerability across dozens of products in multiple quarterly security updates. The CISA KEV entry can be reviewed at the KEV catalog. The ransomware association is unknown, but XSS vulnerabilities in widely deployed libraries are valuable for credential theft, watering hole attacks, and initial access campaigns.
Remediation
-
Upgrade jQuery to version 3.5.0 or later across all web applications and websites. Review the jQuery 3.5.0 release notes and upgrade guide for breaking changes that may affect application functionality. Test thoroughly after upgrading, as the fix changes how jQuery processes HTML during DOM manipulation.
-
Update frameworks and platforms that bundle jQuery to versions that include the patched library. For Drupal, upgrade to versions 7.70, 8.7.14, or 8.8.6 or later. For Oracle products, apply the relevant Critical Patch Update. Check all CMS platforms, JavaScript frameworks, and enterprise applications for jQuery dependency updates.
-
Implement Content Security Policy (CSP) headers as a defense-in-depth measure to mitigate XSS exploitation even on pages that still use vulnerable jQuery versions. Configure CSP to restrict script sources using script-src directives and enable nonce-based or hash-based script allowlisting to prevent execution of injected scripts.
-
Audit all sources of HTML content that are passed to jQuery DOM manipulation methods. Ensure that any user-supplied or third-party HTML is sanitized using a dedicated HTML sanitization library (such as DOMPurify) on the server side before being passed to jQuery methods. Do not rely solely on jQuery's own HTML processing for security.
-
Inventory all jQuery versions deployed across your web infrastructure using automated scanning tools or browser developer tools. Many applications include jQuery through multiple paths — directly, through CDN includes, through bundled node_modules, or through framework dependencies — and each instance must be individually updated or mitigated.
Technical Details
CVE-2020-11023 is a cross-site scripting vulnerability in jQuery, characterized by the CVSS v3.1 vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N. Breaking down the vector components: Attack Vector (AV:N) indicates the vulnerability is exploitable over the network through web pages. Attack Complexity (AC:H) reflects that successful exploitation requires specific conditions — the target application must pass untrusted HTML containing
The technical mechanism involves how jQuery processes HTML strings containing
Frequently Asked Questions
What is CVE-2020-11023?
CVE-2020-11023 is a medium-severity cross-site scripting (XSS) vulnerability in jQuery affecting versions 1.0.3 through 3.4.x. It allows execution of untrusted JavaScript when HTML containing
Why is a 2020 jQuery vulnerability still in CISA's KEV catalog?
jQuery is the most widely deployed JavaScript library in history, and many legacy applications, CMS platforms, and enterprise systems still use vulnerable versions. The continued KEV listing reflects persistent real-world exploitation against the massive install base of unpatched jQuery instances.
Which products are affected beyond jQuery itself?
The vulnerability affects any application using jQuery 1.0.3 through 3.4.x, including Drupal 7 through 8.8.6, dozens of Oracle products, and countless custom web applications. Debian, Fedora, and other Linux distributions have also issued advisories for packages bundling vulnerable jQuery versions.
How do I check if my website uses a vulnerable version of jQuery?
Open your browser developer tools console and type jQuery.fn.jquery or $.fn.jquery to display the jQuery version. If the version is below 3.5.0, you are vulnerable. Note that some pages include multiple jQuery instances, so check all loaded scripts.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.