CISA Digs Up Old jQuery Flaw: Is CVE-2020-11023 the Zombie Vulnerability We Didn’t See Coming?

CISA adds CVE-2020-11023 to its catalog of known exploited vulnerabilities, leaving everyone wondering if they have a time machine. This jQuery flaw, exploited by APT1 ages ago, suddenly gets its time in the spotlight. Federal agencies, don’t forget to RSVP by February 13 to avoid a code-crashing party!

Pro Dashboard

Hot Take:

In a twist worthy of a cybersecurity telenovela, CISA has decided to spice up its Known Exploited Vulnerabilities catalog by adding a jQuery flaw from 2020. It’s like inviting an old flame to the party just to keep things interesting and remind everyone of the good ol’ days when APT1 was the main character in the cyber drama. Let’s just hope they brought some popcorn!

Key Points:

  • CISA added the jQuery flaw CVE-2020-11023 to its Known Exploited Vulnerabilities catalog.
  • The flaw, a medium-severity XSS issue, was disclosed back in April 2020.
  • Major organizations like Linux distributions, IBM, and Atlassian have previously issued advisories.
  • Reports suggest Chinese state-sponsored actor APT1 exploited the flaw in the past.
  • CISA has instructed federal agencies to assess their exposure to the vulnerability by February 13.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?