CVE-2020-11023
Publication date 29 April 2020
Last updated 22 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Read the notes from the security team
Why is this CVE high priority?
Listed in CISA Known Exploited Vulnerabilities Catalog
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| pcs | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| drupal7 | ||
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial |
Fixed 7.44-1ubuntu1~16.04.0+esm3
|
|
| 14.04 LTS trusty |
Fixed 7.26-1ubuntu0.1+esm3
|
|
| jquery | ||
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal |
Fixed 3.3.1~dfsg-3ubuntu0.1
|
|
| 18.04 LTS bionic |
Fixed 3.2.1-1ubuntu0.1~esm1
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
rodrigo-zaiden
priority bumped to high as it was listed in CISA KEV. was previously a low.
yomonokio
pcs vendors jQuery 1.9.1 on xenial/bionic/focal (in range >=1.0.3 <3.5.0) and 3.6.0 on jammy+ (fixed); noble+ ships no jQuery at all. The CVE's mechanism requires the app to sanitize HTML before passing it to .html()/.append() and jQuery to then undo that sanitization; pcsd never sanitizes before these calls, so the specific bypass path is not exercised. Marking not-affected. Caveat: pcsd's own unescaped .html()/.append() calls with server/user-supplied strings are a possible independent first-party XSS concern, out of scope here.
Patch details
| Package | Patch details |
|---|---|
| jquery |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.9 · Medium
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
References
Related Ubuntu Security Notices (USN)
- USN-7246-1
- jQuery vulnerabilities
- 30 January 2025
- USN-7622-1
- jQuery vulnerabilities
- 8 July 2025
- USN-7658-1
- Drupal vulnerabilities
- 21 July 2025