jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces
Published May 19, 2020
5.3
MEDIUMCVSS 4.0
EPSS 6.27%
Description
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
Affected products
- Vendor n/a Product jQuery Defaultn/a
- Version All versions prior to version 1.9.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | jQuery | n/a |
|
Configuration 2
- 8.58
Configuration 3
- n/a
- n/a
- n/a
- n/a
- ≥ 3.0.0 · ≤ 3.1.3
- n/a
No data.
A-MQ Interconnect 1.y for RHEL 6
qpid-dispatch-0:1.13.0-3.el6_10
Fixed · RHSA-2020:4211
A-MQ Interconnect 1.y for RHEL 7
qpid-dispatch-0:1.13.0-3.el7
Fixed · RHSA-2020:4211
A-MQ Interconnect 1.y for RHEL 8
qpid-dispatch-0:1.13.0-3.el8
Fixed · RHSA-2020:4211
Red Hat Enterprise Linux 8
pcs-0:0.10.10-4.el8
Fixed · RHSA-2021:4142
CloudForms Management Engine 5
cfme-gemset
Not affected
OpenShift Service Mesh 1
kiali
Not affected
OpenShift Service Mesh 1
servicemesh-grafana
Not affected
OpenShift Service Mesh 1
servicemesh-prometheus
Not affected
Red Hat 3scale API Management Platform 2
jquery
Will not fix
Red Hat Ceph Storage 3
grafana
Not affected
Red Hat Ceph Storage 3
grafana-container
Not affected
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Not affected
Red Hat Enterprise Linux 6
ipa
Not affected
Red Hat Enterprise Linux 6
pcp
Out of support scope
Red Hat Enterprise Linux 6
pcs
Out of support scope
Red Hat Enterprise Linux 6
python-coverage
Out of support scope
Red Hat Enterprise Linux 6
python-weberror
Out of support scope
Red Hat Enterprise Linux 7
ipa
Not affected
Red Hat Enterprise Linux 7
ipsilon
Out of support scope
Red Hat Enterprise Linux 7
pcp
Will not fix
Red Hat Enterprise Linux 7
pcs
Fix deferred
Red Hat Enterprise Linux 7
pki-core
Not affected
Red Hat Enterprise Linux 7
publican
Will not fix
Red Hat Enterprise Linux 7
python-coverage
Will not fix
Red Hat Enterprise Linux 8
idm:DL1/ipa
Not affected
Red Hat Enterprise Linux 8
pki-core:10.6/pki-core
Not affected
Red Hat Enterprise Linux 9
pcs
Not affected
Red Hat Fuse 7
jquery
Not affected
Red Hat OpenShift Container Platform 3.11
atomic-openshift-web-console
Not affected
Red Hat OpenShift Container Platform 3.11
openshift3/grafana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
Red Hat OpenStack Platform 10 (Newton)
python-XStatic-jQuery
Not affected
Red Hat OpenStack Platform 10 (Newton)
python-XStatic-jquery-ui
Not affected
Red Hat OpenStack Platform 13 (Queens)
python-XStatic-jQuery
Not affected
Red Hat OpenStack Platform 13 (Queens)
python-XStatic-jquery-ui
Not affected
Red Hat OpenStack Platform 15 (Stein)
python-XStatic-jQuery
Not affected
Red Hat OpenStack Platform 15 (Stein)
python-XStatic-jquery-ui
Not affected
Red Hat OpenStack Platform 16 (Train)
python-XStatic-jQuery
Not affected
Red Hat OpenStack Platform 16 (Train)
python-XStatic-jquery-ui
Not affected
Red Hat Process Automation 7
js-jquery
Out of support scope
Red Hat Single Sign-On 7
rh-sso7-keycloak
Not affected
Red Hat Software Collections
python27-python-coverage
Will not fix
Red Hat Software Collections
python27-python-werkzeug
Will not fix
Red Hat Software Collections
rh-python35-python-coverage
Out of support scope
Red Hat Software Collections
rh-python36-python-coverage
Not affected
Red Hat Software Collections
rh-ror42-rubygem-jquery-rails
Out of support scope
Red Hat Software Collections
rh-ror50-rubygem-jquery-rails
Out of support scope
Red Hat Storage 3
grafana
Not affected
Red Hat Virtualization 4
ovirt-engine
Not affected
Red Hat Virtualization 4
ovirt-engine-api-explorer
Not affected
Red Hat Virtualization 4
ovirt-engine-ui-extensions
Not affected
Red Hat Virtualization 4
ovirt-web-ui
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| A-MQ Interconnect 1.y for RHEL 6 | qpid-dispatch-0:1.13.0-3.el6_10 | Fixed | RHSA-2020:4211 |
| A-MQ Interconnect 1.y for RHEL 7 | qpid-dispatch-0:1.13.0-3.el7 | Fixed | RHSA-2020:4211 |
| A-MQ Interconnect 1.y for RHEL 8 | qpid-dispatch-0:1.13.0-3.el8 | Fixed | RHSA-2020:4211 |
| Red Hat Enterprise Linux 8 | pcs-0:0.10.10-4.el8 | Fixed | RHSA-2021:4142 |
| CloudForms Management Engine 5 | cfme-gemset | Not affected | n/a |
| OpenShift Service Mesh 1 | kiali | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-grafana | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-prometheus | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | jquery | Will not fix | n/a |
| Red Hat Ceph Storage 3 | grafana | Not affected | n/a |
| Red Hat Ceph Storage 3 | grafana-container | Not affected | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | ipa | Not affected | n/a |
| Red Hat Enterprise Linux 6 | pcp | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | pcs | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | python-coverage | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | python-weberror | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ipa | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ipsilon | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | pcp | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | pcs | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | pki-core | Not affected | n/a |
| Red Hat Enterprise Linux 7 | publican | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | python-coverage | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | idm:DL1/ipa | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/pki-core | Not affected | n/a |
| Red Hat Enterprise Linux 9 | pcs | Not affected | n/a |
| Red Hat Fuse 7 | jquery | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-web-console | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-XStatic-jquery-ui | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-XStatic-jquery-ui | Not affected | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-XStatic-jquery-ui | Not affected | n/a |
| Red Hat OpenStack Platform 16 (Train) | python-XStatic-jQuery | Not affected | n/a |
| Red Hat OpenStack Platform 16 (Train) | python-XStatic-jquery-ui | Not affected | n/a |
| Red Hat Process Automation 7 | js-jquery | Out of support scope | n/a |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Not affected | n/a |
| Red Hat Software Collections | python27-python-coverage | Will not fix | n/a |
| Red Hat Software Collections | python27-python-werkzeug | Will not fix | n/a |
| Red Hat Software Collections | rh-python35-python-coverage | Out of support scope | n/a |
| Red Hat Software Collections | rh-python36-python-coverage | Not affected | n/a |
| Red Hat Software Collections | rh-ror42-rubygem-jquery-rails | Out of support scope | n/a |
| Red Hat Software Collections | rh-ror50-rubygem-jquery-rails | Out of support scope | n/a |
| Red Hat Storage 3 | grafana | Not affected | n/a |
| Red Hat Virtualization 4 | ovirt-engine | Not affected | n/a |
| Red Hat Virtualization 4 | ovirt-engine-api-explorer | Not affected | n/a |
| Red Hat Virtualization 4 | ovirt-engine-ui-extensions | Not affected | n/a |
| Red Hat Virtualization 4 | ovirt-web-ui | Not affected | n/a |
jQuery
NuGet
Introduced 1.2.1 Fixed 1.9.0jquery-rails
RubyGems
Introduced 0 Fixed 2.2.0org.webjars.npm:jquery
Maven
Introduced 1.2.1 Fixed 1.9.0jquery
npm
Introduced 1.2.1 Fixed 1.9.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| NuGet | jQuery | 1.2.1 | 1.9.0 |
| RubyGems | jquery-rails | 0 | 2.2.0 |
| Maven | org.webjars.npm:jquery | 1.2.1 | 1.9.0 |
| npm | jquery | 1.2.1 | 1.9.0 |
Remediation
Red Hat statement
Red Hat Enterprise Linux version 6, 7 and 8 ship a vulnerable version of JQuery in the `pcs` component. However the vulnerable has not been found to be exploitable in reasonable scenarios. A future update may update JQuery to a fixed version.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.27% (0.06273) | 93.37th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.27% (0.06273) | 92.65th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.15% (0.00154) | 52.13th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.15% (0.00154) | 50.43th | v3 (v2023.03.01) |
| Jun 23, 2023 | 0.22% (0.00224) | 59.46th | v3 (v2023.03.01) |
| Jun 14, 2023 | 0.17% (0.00166) | 52.05th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.10% (0.00103) | 40.51th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Feb 22, 2023 | 0.95% (0.00954) | 36.13th | v2 (v2022.01.01) |
| Jul 26, 2022 | 0.95% (0.00954) | 34.06th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 6.72% (0.06722) | 78.75th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v1 |
| Jan 6, 2022 | 2.74% (0.02742) | 62.72th | v1 |
| Sep 1, 2021 | 0.62% (0.00624) | 45.04th | v1 |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (15)
- https://access.redhat.com/security/cve/CVE-2020-7656 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1850119 Issue Tracking
- https://github.com/advisories/GHSA-q4m3-2j7h-f7xw Advisory
- https://github.com/jquery/jquery/blob/9e6393b0bcb52b15313f88141d0bd7dd54227426/src/ajax.js#L203
- https://github.com/jquery/jquery/commit/05531fc4080ae24070930d15ae0cea7ae056457d
- https://github.com/jquery/jquery/commit/606b863edaff29035960e4d813b45d63b8d92876
- https://github.com/rails/jquery-rails/blob/master/CHANGELOG.md#220-19-january-2013
- https://github.com/rails/jquery-rails/blob/v2.1.4/vendor/assets/javascripts/jquery.js#L7481
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-rails/CVE-2020-7656.yml
- https://nvd.nist.gov/vuln/detail/CVE-2020-7656
- https://security.netapp.com/advisory/ntap-20200528-0001 Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JQUERY-569619 ExploitThird Party Advisory
- https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1?language=en_US Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7656
- https://www.oracle.com/security-alerts/cpujul2022.html Third Party Advisory
Change history (0)
No recorded changes yet.