{"id":"GHSA-v73w-r9xg-7cr9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v73w-r9xg-7cr9","summary":"Use of insecure jQuery version in OctoberCMS","details":"### Impact\nPassing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.\n\n### Patches\nIssue has been patched in Build 466 (v1.0.466) by applying the recommended patch from @jquery.\n\n### Workarounds\nApply https://github.com/octobercms/october/commit/5c7ba9fbe9f2b596b2f0e3436ee06b91b97e5892 to your installation manually if unable to upgrade to Build 466.\n\n### References\n- https://github.com/jquery/jquery/security/advisories/GHSA-gxr4-xjj5-5px2\n- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11022\n- https://jquery.com/upgrade-guide/3.5/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [octobercms@luketowers.ca](mailto:octobercms@luketowers.ca) & [hello@octobercms.com](mailto:hello@octobercms.com)\n\n### Threat Assessment\nAssessed as Moderate by the @jquery team.\n\n### Acknowledgements\n\nThanks to @mrgswift for reporting the issue to the October CMS team.","published":"2020-06-05T19:37:49Z","modified":"2024-12-02T05:55:28.298795Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"october/october","fixedVersion":"1.0.466"},{"ecosystem":"Packagist","name":"october/system","fixedVersion":"1.0.466"}],"fix":{"url":"https://github.com/octobercms/october/commit/5c7ba9fbe9f2b596b2f0e3436ee06b91b97e5892","label":"octobercms/october@5c7ba9f"},"references":[{"type":"WEB","url":"https://github.com/octobercms/october/security/advisories/GHSA-v73w-r9xg-7cr9"},{"type":"WEB","url":"https://github.com/octobercms/october/issues/5097"},{"type":"WEB","url":"https://github.com/octobercms/october/commit/5c7ba9fbe9f2b596b2f0e3436ee06b91b97e5892"},{"type":"PACKAGE","url":"https://github.com/octobercms/october"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:55:28.298795Z"}}