Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-11022

83
FAUCET Score

CVE-2020-11022 is a Cross-Site Scripting (XSS) vulnerability affecting jQuery versions prior to 3.5.0, where passing unsanitized HTML from untrusted sources to DOM manipulation methods can lead to arbitrary code execution. This impacts various products including Debian, Drupal, and Oracle that utilize vulnerable jQuery versions. Rated with a CVSS score of 6.1 (Medium), the vulnerability has a network attack vector and low attack complexity, requiring user interaction to exploit. Successful exploitation could lead to limited confidentiality and integrity impacts, as indicated by the CVSS vector. While not listed on the CISA KEV catalog or Hot List, an ExploitDB entry (EDB-49766) exists, confirming exploit code availability. The vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.2, < 3.5.0CPE matchmatch criteria
cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*
>= 7.0, < 7.70CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
>= 8.7.0, < 8.7.14CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
>= 8.8.0, < 8.8.6CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.02%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-49766 · Apr 14, 2021
This CVE's current EPSS score of 0.9902 is in the 100th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (50)

composerpatch availablevia ghsa
Product: athlon1600/youtube-downloaderFixed in: 4.0.1
composerpatch availablevia ghsa
Product: components/jqueryFixed in: 3.5.0
composerpatch availablevia ghsa
Product: maximebf/debugbarFixed in: 1.19.0
github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.webjars.npm:jqueryFixed in: 3.5.0
npmpatch availablevia ghsa
Product: jqueryFixed in: 3.5.0
nugetpatch availablevia ghsa
Product: jqueryFixed in: 3.5.0
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: ovirt-engine-ui-extensions-0:1.2.2-1.el8ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-web-console-0:3.11.219-1.git.1.9b9b889.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift4/ose-console:v4.5.0-202007012112.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-grafana:v4.6.0-202010061132.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-prometheus:v4.6.0-202009290409.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: keycloak-idp-jquery
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 7Fixed in: rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 8Fixed in: rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 9Fixed in: rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: ovirt-web-ui-0:1.6.4-1.el8ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: org.ovirt.engine-root-0:4.5.2.4-1
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rh-sso-7/sso76-openshift-rhel8:7.6-20
View patch
redhatpatch availablevia redhat_api
Product: A-MQ Interconnect 1.y for RHEL 6Fixed in: qpid-dispatch-0:1.13.0-3.el6_10
View patch
redhatpatch availablevia redhat_api
Product: A-MQ Interconnect 1.y for RHEL 7Fixed in: qpid-dispatch-0:1.13.0-3.el7
View patch
redhatpatch availablevia redhat_api
Product: A-MQ Interconnect 1.y for RHEL 8Fixed in: qpid-dispatch-0:1.13.0-3.el8
View patch
redhatpatch availablevia redhat_api
Product: Openshift Service Mesh 1.0Fixed in: jaeger-0:v1.13.1.redhat7-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Openshift Service Mesh 1.0Fixed in: kiali-0:v1.0.11.redhat1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-grafana-0:6.2.2-36.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.6 for RHEL 7Fixed in: ansible-tower-36/ansible-tower:3.6.7-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.7 for RHEL 7Fixed in: ansible-tower-37/ansible-tower-rhel7:3.7.4-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ipa-0:4.6.8-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: idm:client-8030020200923172426.05ac3f11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: idm:DL1-8030020200923172343.9c827e52
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-core:10.6-8030020200911215836.5ff1562f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-deps:10.6-8030020200527165326.30b713e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jquery
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el7eap
View patch
rubygemspatch availablevia ghsa
Product: jquery-railsFixed in: 4.4.0
redhatvendor investigatingvia redhat_api
Product: Red Hat Virtualization 4Fixed in: ovirt-js-dependencies
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhel8/grafana
redhatno patchvia redhat_api
Product: Red Hat Virtualization 4Fixed in: ovirt-engine
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: python27-python-coverage
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python-coverage
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: python27-python-werkzeug
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: pcs
redhatend of lifevia redhat_api
Product: CloudForms Management Engine 5Fixed in: cfme-gemset
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: python-testtools
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: jquery
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/grafana

Vendor Advisories (3)

npmGHSA-gxr4-xjj5-5px2medium

Potential XSS vulnerability in jQuery

Apr 29, 2020
rubygemsGHSA-gxr4-xjj5-5px2medium

Potential XSS vulnerability in jQuery

Apr 29, 2020
redhatCVE-2020-11022Moderate

jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method

Apr 23, 2020

References

lists.opensuse.org / opensuse-security-announce/2020-07/msg00067.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2020-07/msg00085.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2020-11/msg00039.html
Broken Link
packetstormsecurity.com / files/162159/jQuery-1.2-Cross-Site-Scripting.html
ExploitThird Party AdvisoryVDB Entry
blog.jquery.com / 2020/04/10/jquery-3-5-0-released
Release NotesVendor Advisory
jquery.com / upgrade-guide/3.5
MitigationVendor Advisory
lists.apache.org / thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36%40%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48%40%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae%40%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760%40%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d%40%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c%40%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67%40%3Cdev.flink.apache.org%3E
lists.apache.org / thread.html/rdf44341677cf7eec7e9aa96dcf3f37ed709544863d619cca8c36f133%40%3Ccommits.airflow.apache.org%3E
lists.apache.org / thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108%40%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4%40%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2%40%3Cissues.flink.apache.org%3E
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W
security.netapp.com / advisory/ntap-20200511-0006
Third Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
blog.jquery.com / 2020/04/10/jquery-3-5-0-released
security.netapp.com / advisory/ntap-20200511-0006
github.com / jquery/jquery/commit/1d61fd9407e6fbe82fe55cb0b938307aa0791f77
PatchThird Party Advisory
github.com / jquery/jquery/releases/tag/3.5.0
github.com / jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2
MitigationThird Party Advisory
github.com / maximebf/php-debugbar/commit/847216e60544258c881f2733d699bbcfeefac0fc
github.com / maximebf/php-debugbar/issues/447
github.com / rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2020-11022.yml
jquery.com / upgrade-guide/3.5
lists.apache.org / thread.html/r0483ba0072783c2e1bfea613984bfb3c86e73ba8879d780dc1cc7d36@%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r49ce4243b4738dd763caeb27fa8ad6afb426ae3e8c011ff00b8b1f48@%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r54565a8f025c7c4f305355fdfd75b68eca442eebdb5f31c2e7d977ae@%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r564585d97bc069137e64f521e68ba490c7c9c5b342df5d73c49a0760@%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r706cfbc098420f7113968cc377247ec3d1439bce42e679c11c609e2d@%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/r8f70b0f65d6bedf316ecd899371fd89e65333bc988f6326d2956735c@%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/rbb448222ba62c430e21e13f940be4cb5cfc373cd3bce56b48c0ffa67@%3Cdev.flink.apache.org%3E
lists.apache.org / thread.html/rdf44341677cf7eec7e9aa96dcf3f37ed709544863d619cca8c36f133@%3Ccommits.airflow.apache.org%3E
lists.apache.org / thread.html/re4ae96fa5c1a2fe71ccbb7b7ac1538bd0cb677be270a2bf6e2f8d108@%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/rede9cfaa756e050a3d83045008f84a62802fc68c17f2b4eabeaae5e4@%3Cissues.flink.apache.org%3E
lists.apache.org / thread.html/ree3bd8ddb23df5fa4e372d11c226830ea3650056b1059f3965b3fce2@%3Cissues.flink.apache.org%3E
lists.debian.org / debian-lts-announce/2021/03/msg00033.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/08/msg00040.html
lists.fedoraproject.org / archives/list/[email protected]/message/AVKYXLWCLZBV2N7M46KYK4LVA5OXWPBY
lists.fedoraproject.org / archives/list/[email protected]/message/QPN2L2XVQGUA2V5HNQJWHK3APSK3VN7K
lists.fedoraproject.org / archives/list/[email protected]/message/SAPQVX3XDNPGFT26QAQ6AJIXZZBZ4CD4
lists.fedoraproject.org / archives/list/[email protected]/message/SFP4UK4EGP4AFH2MWYJ5A5Z4I7XVFQ6B
lists.fedoraproject.org / archives/list/[email protected]/message/VOE7P7APPRQKD4FGNHBKJPDY6FFCOH3W
lists.opensuse.org / opensuse-security-announce/2020-07/msg00067.html
lists.opensuse.org / opensuse-security-announce/2020-07/msg00085.html
lists.opensuse.org / opensuse-security-announce/2020-11/msg00039.html
packetstormsecurity.com / files/162159/jQuery-1.2-Cross-Site-Scripting.html
security.gentoo.org / glsa/202007-03
Third Party Advisory
debian.org / security/2020/dsa-4693
Third Party Advisory
drupal.org / sa-core-2020-002
Third Party Advisory
oracle.com / security-alerts/cpuApr2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2021.html
Third Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2020.html
Third Party Advisory
oracle.com / security-alerts/cpujul2021.html
oracle.com / security-alerts/cpujul2022.html
oracle.com / security-alerts/cpuoct2020.html
Third Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory
tenable.com / security/tns-2020-10
Third Party Advisory
tenable.com / security/tns-2020-11
Third Party Advisory
tenable.com / security/tns-2021-02
Third Party Advisory
tenable.com / security/tns-2021-10
Third Party Advisory