CISA Digs Up Old jQuery Flaw: Is CVE-2020-11023 the Zombie Vulnerability We Didn’t See Coming?
CISA adds CVE-2020-11023 to its catalog of known exploited vulnerabilities, leaving everyone wondering if they have a time machine. This jQuery flaw, exploited by APT1 ages ago, suddenly gets its time in the spotlight. Federal agencies, don’t forget to RSVP by February 13 to avoid a code-crashing party!

Hot Take:
In a twist worthy of a cybersecurity telenovela, CISA has decided to spice up its Known Exploited Vulnerabilities catalog by adding a jQuery flaw from 2020. It’s like inviting an old flame to the party just to keep things interesting and remind everyone of the good ol’ days when APT1 was the main character in the cyber drama. Let’s just hope they brought some popcorn!
Key Points:
- CISA added the jQuery flaw CVE-2020-11023 to its Known Exploited Vulnerabilities catalog.
- The flaw, a medium-severity XSS issue, was disclosed back in April 2020.
- Major organizations like Linux distributions, IBM, and Atlassian have previously issued advisories.
- Reports suggest Chinese state-sponsored actor APT1 exploited the flaw in the past.
- CISA has instructed federal agencies to assess their exposure to the vulnerability by February 13.
Already a member? Log in here