CVE-2020-23064: XSS
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-jpcq-cgw6-v4j6. This link is maintained to preserve external references.
Original Description
Cross Site Scripting vulnerability in jQuery v.2.2.0 until v.3.5.0 allows a remote attacker to execute arbitrary code via the <options> element.
Other sources
Cross Site Scripting vulnerability in jQuery 2.2.0 through 3.x before 3.5.0 allows a remote attacker to execute arbitrary code via the <options> element.
Cross Site Scripting vulnerability in jQuery v.2.2.0 thru v.3.5.0 allows a remote attacker to execute arbitrary code via the <options> element.
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ https://snyk.io/vuln/SNYK-JS-JQUERY-565129
— Red Hat
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11023. Reason: This candidate is a duplicate of CVE-2020-11023. Notes: All CVE users should reference CVE-2020-11023 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this cross-site scripting vulnerability?
The vulnerability ID for this cross-site scripting vulnerability is CVE-2020-23064.
What is the severity level of CVE-2020-23064?
The severity level of CVE-2020-23064 is medium.
Which versions of jQuery are affected by CVE-2020-23064?
Versions 2.2.0 through 3.x before 3.5.0 of jQuery are affected by CVE-2020-23064.
How can a remote attacker exploit CVE-2020-23064?
A remote attacker can exploit CVE-2020-23064 by executing arbitrary code via the <options> element.
Are there any references available for CVE-2020-23064?
Yes, there are references available for CVE-2020-23064. You can find them at the following links: [Link 1](https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/), [Link 2](https://security.netapp.com/advisory/ntap-20230725-0003/), and [Link 3](https://snyk.io/vuln/SNYK-JS-JQUERY-565129).