• 公告ID (KylinSec-SA-2024-3411)

摘要:

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option&gt; elements from untrusted sources - even after sanitizing it - to one of jQuery s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

安全等级: Low

公告ID: KylinSec-SA-2024-3411

发布日期: 2024年8月22日

关联CVE: CVE-2020-11023  

  • 详细介绍

1. 漏洞描述

   

In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option&gt; elements from untrusted sources - even after sanitizing it - to one of jQuery s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2020-11023 KY3.4-5A js-jquery Unaffected
CVE-2020-11023 KY3.5.2 js-jquery Unaffected
CVE-2020-11023 V6 js-jquery Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-3410 下一篇:KylinSec-SA-2024-3412