VDB
RHSA-2025%3A1983
RHSA-2025%3A1983
PUBLISHED
CVSS 6.099999904632568 MEDIUM
A flaw was found in jQuery. HTML containing \<option\> elements from untrusted sources are passed, even after sanitizing, to one of jQuery's DOM manipulation methods, which may execute untrusted code. The highest threat from this vulnerability is to data confidentiality and integrity.
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/kibana6-rhel8@sha256:571d43bc602450e0883ec5aa3e7d44a00413be545ab4c0a67db48cd7c1e77b3b_ppc64le as a component of RHOL 5.8 for RHEL 8 | *, openshift-logging/kibana6-rhel8@sha256:571d43bc602450e0883ec5aa3e7d44a00413be545ab4c0a67db48cd7c1e77b3b_ppc64le |
| Red Hat | openshift-logging/kibana6-rhel8@sha256:fff31521cd7e8533be31f39eda05d47fb8986fbeb144819cec3761e3b1e1ba32_amd64 as a component of RHOL 5.8 for RHEL 8 | *, openshift-logging/kibana6-rhel8@sha256:fff31521cd7e8533be31f39eda05d47fb8986fbeb144819cec3761e3b1e1ba32_amd64 |
| Red Hat | openshift-logging/kibana6-rhel8@sha256:3edcb9e5f595f43560c2d1a9cd643ba3a47052d64d02ffb239aa514444c7ffca_arm64 as a component of RHOL 5.8 for RHEL 8 | *, openshift-logging/kibana6-rhel8@sha256:3edcb9e5f595f43560c2d1a9cd643ba3a47052d64d02ffb239aa514444c7ffca_arm64 |
| Red Hat | openshift-logging/kibana6-rhel8@sha256:11bfe43b2b6372dfedee47ef10ec0ec67bb7070265f579dd512a36e2ff691ff6_s390x as a component of RHOL 5.8 for RHEL 8 | *, openshift-logging/kibana6-rhel8@sha256:11bfe43b2b6372dfedee47ef10ec0ec67bb7070265f579dd512a36e2ff691ff6_s390x |
Timeline
- Mar 5, 2025 CVE Published
- May 10, 2026 Distribution Patch
- May 10, 2026 Distribution Patch
- May 10, 2026 Security Advisory
- May 10, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:1983 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1983.json advisory
- https://access.redhat.com/security/cve/CVE-2020-11023 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1850004 issue
- https://www.cve.org/CVERecord?id=CVE-2020-11023 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-11023 advisory
- https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/ advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit