摘要:
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
安全等级: Low
公告ID: KylinSec-SA-2024-3411
发布日期: 2024年8月22日
关联CVE: CVE-2020-11023
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery s DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2020-11023 | KY3.4-5A | js-jquery | Unaffected |
CVE-2020-11023 | KY3.5.2 | js-jquery | Unaffected |
CVE-2020-11023 | V6 | js-jquery | Unaffected |