In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0. References: https://blog.jquery.com/2020/04/10/jquery-3-5-0-released https://github.com/jquery/jquery/security/advisories/GHSA-jpcq-cgw6-v4j6 https://jquery.com/upgrade-guide/3.5/ https://security.netapp.com/advisory/ntap-20200511-0006/ https://www.debian.org/security/2020/dsa-4693 https://www.drupal.org/sa-core-2020-002
Created drupal7 tracking bugs for this issue: Affects: epel-all [bug 1850023] Affects: fedora-all [bug 1850013] Created js-jquery tracking bugs for this issue: Affects: epel-7 [bug 1850008] Affects: fedora-all [bug 1850015] Created js-jquery1 tracking bugs for this issue: Affects: epel-7 [bug 1850006] Affects: fedora-all [bug 1850022] Created js-jquery2 tracking bugs for this issue: Affects: fedora-all [bug 1850016] Created python-XStatic-jQuery tracking bugs for this issue: Affects: epel-7 [bug 1850007] Affects: fedora-all [bug 1850018] Affects: openstack-rdo [bug 1850011] Created python-XStatic-jquery-ui tracking bugs for this issue: Affects: epel-7 [bug 1850010] Affects: fedora-all [bug 1850017] Affects: openstack-rdo [bug 1850012] Created python-tw-jquery tracking bugs for this issue: Affects: epel-6 [bug 1850014] Created python-tw2-jquery tracking bugs for this issue: Affects: epel-6 [bug 1850021] Affects: epel-7 [bug 1850009] Affects: fedora-all [bug 1850020] Created rubygem-jquery-rails tracking bugs for this issue: Affects: fedora-all [bug 1850019]
OpenShift ServiceMesh includes a vulnerable version of jquery (3.4.1) in servicemesh-grafana.
[edited] Upstream fix: https://github.com/jquery/jquery/commit/966a70909019aa09632c87c0002c522fa4a1e30e In the advisory from jquery they talk about removing the regex functionality from htmlPrefilter, "The jQuery.htmlPrefilter function does not use a regex in 3.5.0 and passes the string through unchanged."
Further to #comment8 grafana actually do package jquery 3.5.0, included as a patch in the RPM and hence is not affected.
External References: https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
Below storage products includes vulnerable version of jQuery in grafana and grafana-container: Ceph-3 grafana : jquery-3.3.1 Ceph-3 grafana-container : jquery-3.3.1 Ceph-4 grafana-container : jquery-3.3.1 Gluster grafana : jquery-3.2.1
This issue has been addressed in the following products: Red Hat Single Sign-On 7.4.1 Via RHSA-2020:2813 https://access.redhat.com/errata/RHSA-2020:2813
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-11023
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.5 Via RHSA-2020:2412 https://access.redhat.com/errata/RHSA-2020:2412
This issue has been addressed in the following products: Red Hat Virtualization Engine 4.4 Via RHSA-2020:3247 https://access.redhat.com/errata/RHSA-2020:3247
This issue has been addressed in the following products: OpenShift Service Mesh 1.1 Openshift Service Mesh 1.1 Via RHSA-2020:3369 https://access.redhat.com/errata/RHSA-2020:3369
This issue has been addressed in the following products: Red Hat Virtualization Engine 4.4 Via RHSA-2020:3807 https://access.redhat.com/errata/RHSA-2020:3807
Created pcs tracking bugs for this issue: Affects: fedora-all [bug 1882296]
This issue has been addressed in the following products: A-MQ Interconnect 1.y for RHEL 7 A-MQ Interconnect 1.y for RHEL 6 A-MQ Interconnect 1.y for RHEL 8 Via RHSA-2020:4211 https://access.redhat.com/errata/RHSA-2020:4211
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.6 Via RHSA-2020:4298 https://access.redhat.com/errata/RHSA-2020:4298
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:4847 https://access.redhat.com/errata/RHSA-2020:4847
This issue has been addressed in the following products: Red Hat Ansible Tower 3.7 for RHEL 7 Via RHSA-2020:5249 https://access.redhat.com/errata/RHSA-2020:5249
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2020:5412 https://access.redhat.com/errata/RHSA-2020:5412
Statement: Red Hat Enterprise Linux version 6, 7, and 8 ship a vulnerable version of JQuery in the `pcs` component. However the vulnerability has not been found to be exploitable in reasonable scenarios. A future update may update JQuery to a fixed version.
This issue has been addressed in the following products: Red Hat Ansible Tower 3.6 for RHEL 7 Via RHSA-2021:0778 https://access.redhat.com/errata/RHSA-2021:0778
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:0860 https://access.redhat.com/errata/RHSA-2021:0860
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1846 https://access.redhat.com/errata/RHSA-2021:1846
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4142 https://access.redhat.com/errata/RHSA-2021:4142
This issue has been addressed in the following products: Red Hat Virtualization Engine 4.4 Via RHSA-2022:6393 https://access.redhat.com/errata/RHSA-2022:6393
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2023:0553 https://access.redhat.com/errata/RHSA-2023:0553
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2023:0552 https://access.redhat.com/errata/RHSA-2023:0552
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2023:0554 https://access.redhat.com/errata/RHSA-2023:0554
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2023:0556 https://access.redhat.com/errata/RHSA-2023:0556