jquery: Cross-site scripting
Published Jun 26, 2023
6.3
MEDIUMCVSS 3.1
EPSS 0.04%
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11023. Reason: This candidate is a duplicate of CVE-2020-11023. Notes: All CVE users should reference CVE-2020-11023 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Affected products
No data.
No data.
No data.
Red Hat AMQ Broker 7.13.0
hawtio-core
Fixed · RHSA-2025:7625
Red Hat Ceph Storage 3
grafana
Out of support scope
Red Hat Certificate System 10
redhat-pki:10/pki-core
Not affected
Red Hat Certificate System 10
redhat-pki:10/pki-extras
Not affected
Red Hat Certificate System 10
redhat-pki:10/redhat-pki
Not affected
Red Hat Certification for Red Hat Enterprise Linux 6
redhat-certification-backend
Will not fix
Red Hat Certification for Red Hat Enterprise Linux 7
python-testtools
Will not fix
Red Hat Certification for Red Hat Enterprise Linux 7
redhat-certification
Will not fix
Red Hat Decision Manager 7
jquery
Out of support scope
Red Hat Discovery 1
discovery-server-container
Affected
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 7
thunderbird
Not affected
Red Hat Enterprise Linux 8
cockpit-session-recording
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 8
mozjs60
Not affected
Red Hat Enterprise Linux 8
pcs
Affected
Red Hat Enterprise Linux 8
pki-core:10.6/pki-core
Not affected
Red Hat Enterprise Linux 8
tbb
Not affected
Red Hat Enterprise Linux 9
cockpit-session-recording
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Enterprise Linux 9
pki-core
Not affected
Red Hat Enterprise Linux 9
polkit
Not affected
Red Hat Enterprise Linux 9
tbb
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat Fuse 7
hawtio-core
Will not fix
Red Hat JBoss Data Grid 7
jquery
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_2-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jquery
Not affected
Red Hat JBoss Enterprise Application Platform 8
jquery
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jquery
Not affected
Red Hat OpenShift Container Platform 3.11
openshift3/ose-console
Out of support scope
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Not affected
Red Hat OpenShift Container Platform 4
python-testtools
Affected
Red Hat OpenStack Platform 13 (Queens)
python-django
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
python-testtools
Out of support scope
Red Hat OpenStack Platform 16.1
python-django20
Will not fix
Red Hat OpenStack Platform 16.1
qpid-dispatch
Not affected
Red Hat OpenStack Platform 16.2
python-django20
Will not fix
Red Hat OpenStack Platform 16.2
qpid-dispatch
Not affected
Red Hat OpenStack Platform 17.0
python-django
Not affected
Red Hat OpenStack Platform 17.0
python-testtools
Not affected
Red Hat OpenStack Platform 17.1
python-django
Not affected
Red Hat OpenStack Platform 17.1
python-pygraphviz
Not affected
Red Hat OpenStack Platform 17.1
python-testtools
Not affected
Red Hat OpenStack Platform 18.0
python-django
Not affected
Red Hat OpenStack Platform 18.0
python-testtools
Not affected
Red Hat Process Automation 7
jquery
Not affected
Red Hat Quay 3
quay/quay-rhel8
Will not fix
Red Hat Satellite 6
nodejs-jquery
Affected
Red Hat Satellite 6
nodejs-patternfly-react-catalog-view-extension
Not affected
Red Hat Single Sign-On 7
jquery
Not affected
Red Hat Storage 3
grafana
Will not fix
Red Hat Storage 3
python-django
Will not fix
Red Hat Storage 3
python-testtools
Will not fix
Red Hat Virtualization 4
cockpit-ovirt
Not affected
Red Hat Virtualization 4
ovirt-web-ui
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Broker 7.13.0 | hawtio-core | Fixed | RHSA-2025:7625 |
| Red Hat Ceph Storage 3 | grafana | Out of support scope | n/a |
| Red Hat Certificate System 10 | redhat-pki:10/pki-core | Not affected | n/a |
| Red Hat Certificate System 10 | redhat-pki:10/pki-extras | Not affected | n/a |
| Red Hat Certificate System 10 | redhat-pki:10/redhat-pki | Not affected | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 6 | redhat-certification-backend | Will not fix | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 7 | python-testtools | Will not fix | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 7 | redhat-certification | Will not fix | n/a |
| Red Hat Decision Manager 7 | jquery | Out of support scope | n/a |
| Red Hat Discovery 1 | discovery-server-container | Affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit-session-recording | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pcs | Affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/pki-core | Not affected | n/a |
| Red Hat Enterprise Linux 8 | tbb | Not affected | n/a |
| Red Hat Enterprise Linux 9 | cockpit-session-recording | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | pki-core | Not affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
| Red Hat Enterprise Linux 9 | tbb | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat Fuse 7 | hawtio-core | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | jquery | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_2-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jquery | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jquery | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jquery | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | python-testtools | Affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-django | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-testtools | Out of support scope | n/a |
| Red Hat OpenStack Platform 16.1 | python-django20 | Will not fix | n/a |
| Red Hat OpenStack Platform 16.1 | qpid-dispatch | Not affected | n/a |
| Red Hat OpenStack Platform 16.2 | python-django20 | Will not fix | n/a |
| Red Hat OpenStack Platform 16.2 | qpid-dispatch | Not affected | n/a |
| Red Hat OpenStack Platform 17.0 | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 17.0 | python-testtools | Not affected | n/a |
| Red Hat OpenStack Platform 17.1 | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 17.1 | python-pygraphviz | Not affected | n/a |
| Red Hat OpenStack Platform 17.1 | python-testtools | Not affected | n/a |
| Red Hat OpenStack Platform 18.0 | python-django | Not affected | n/a |
| Red Hat OpenStack Platform 18.0 | python-testtools | Not affected | n/a |
| Red Hat Process Automation 7 | jquery | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Will not fix | n/a |
| Red Hat Satellite 6 | nodejs-jquery | Affected | n/a |
| Red Hat Satellite 6 | nodejs-patternfly-react-catalog-view-extension | Not affected | n/a |
| Red Hat Single Sign-On 7 | jquery | Not affected | n/a |
| Red Hat Storage 3 | grafana | Will not fix | n/a |
| Red Hat Storage 3 | python-django | Will not fix | n/a |
| Red Hat Storage 3 | python-testtools | Will not fix | n/a |
| Red Hat Virtualization 4 | cockpit-ovirt | Not affected | n/a |
| Red Hat Virtualization 4 | ovirt-web-ui | Not affected | n/a |
jquery
npm
Introduced 1.0.3 Fixed 3.5.0jQuery
NuGet
Introduced 1.0.3 Fixed 3.5.0jquery-rails
RubyGems
Introduced 0 Fixed 4.4.0org.webjars.npm:jquery
Maven
Introduced 1.0.3 Fixed 3.5.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | jquery | 1.0.3 | 3.5.0 |
| NuGet | jQuery | 1.0.3 | 3.5.0 |
| RubyGems | jquery-rails | 0 | 4.4.0 |
| Maven | org.webjars.npm:jquery | 1.0.3 | 3.5.0 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Dec 12, 2024.
Score over time
2023–2024- EPSS v3
Percentile over time
- EPSS v3
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Dec 12, 2024 | 0.04% (0.00045) | 17.85th | v3 (v2023.03.01) |
| Jul 20, 2024 | 0.04% (0.00045) | 16.18th | v3 (v2023.03.01) |
| Jun 27, 2023 | 0.05% (0.00053) | 18.96th | v3 (v2023.03.01) |
References (4)
- https://access.redhat.com/security/cve/CVE-2020-23064 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2217733 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2020-23064
- https://www.cve.org/CVERecord?id=CVE-2020-23064
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-23064 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2217733 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-23064 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-23064 |
Change history (0)
No recorded changes yet.