cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2379
Views
0
Helpful
3
Replies

CVE-2020-11022 on WLC 8.10.130

richard.greene1
Beginner
Beginner

JQUERY <3.5

Our security team has informed us that the 3504 running 8.10.130 is showing as vulnerable for the issue identified in CVE-2020-11022

 

In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

3 Replies 3

Leo Laohoo
Hall of Fame
Hall of Fame

From what I can read, CVE-2020-11022/CVE-2020-11023 only affects Cisco Unified Presence, UCSM and APIC. 

I don't see anything mentioning about AireOS.