JQuery’s Five-Year Itch: Old Bug Crawls Back to Haunt Cybersecurity!

CISA adds a patched jQuery security flaw to its KEV catalog due to active exploitation. This five-year-old vulnerability, CVE-2020-11023, is now making waves. The bug could lead to arbitrary code execution if left unchecked. Agencies are advised to take action by February 2025 to tighten their digital fortresses.

Pro Dashboard

Hot Take:

Looks like jQuery’s old bug is back with a vengeance, proving once again that even in the world of cybersecurity, age is just a number – especially when it comes to vulnerabilities! While some folks are collecting vintage records, cybercriminals are dusting off vintage exploits. Who knew web security could be so retro?

Key Points:

  • CISA added the five-year-old jQuery vulnerability to its Known Exploited Vulnerabilities catalog.
  • The vulnerability, CVE-2020-11023, is a cross-site scripting (XSS) bug.
  • jQuery version 3.5.0, released in April 2020, patched the flaw.
  • EclecticIQ identified the flaw’s use in real-world attacks in 2024.
  • FCEB agencies have until February 13, 2025, to address the vulnerability.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?