Junglewise Threat Intelligence

CVE-2020-11022: jQuery XSS in DOM manipulation methods

CVE-2020-11022 · Severity: medium · CVSS 6.9 · Published 2020-04-29

Technologies: jQuery, Rubysec Jquery-Rails, org.webjars.npm:jquery (Maven). Vendors: jQuery, Packagist, Maven, RubyGems.

Executive brief

jQuery is a widely used JavaScript library that helps websites display and manipulate content. A security flaw exists where the library may accidentally execute malicious code when processing web content from untrusted sources, even if that content was previously cleaned. This could allow an attacker to steal user session information or perform unauthorized actions on behalf of a visitor to a vulnerable website.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in jQuery's DOM manipulation methods, such as .html() and .append(). The issue stems from how jQuery handles HTML strings containing certain tags, which can bypass sanitization logic when processed through jQuery's internal pre-filtering mechanisms. An attacker can exploit this by providing specially crafted HTML that, when passed to these methods, executes arbitrary JavaScript in the context of the victim's browser. This vulnerability is tracked as CVE-2020-11022 and is resolved in jQuery version 3.5.0. A workaround is available for older versions (1.12/2.2+) by overriding jQuery.htmlPrefilter to return the input unchanged.

Affected products

  • jquery jquery >= 1.12.0, < 3.5.0
  • rubysec jquery-rails < 4.4.0
  • maximebf debugbar < 1.19.0

Timeline

  • 2020-04-10: patched: jQuery 3.5.0 released
  • 2020-04-29: disclosed: GitHub Advisory published

References

Related threats