Package: znc
Version: 1.10.2-1
Severity: important
Tags: security
X-Debbugs-Cc: [email protected], [email protected]

The ZNC web interface ships a bundled copy of jQuery 1.11.2 at:
  webskins/_default_/pub/jquery-1.11.2.js

This version is vulnerable to XSS via DOM manipulation methods
(CVE-2020-11022, CVE-2020-11023, fixed in jQuery 3.5.0). Since ZNC
actively serves this file to users via its web interface, the XSS
vulnerability is exploitable via the ZNC web UI.

Please update the bundled jQuery to 3.5.0 or later, or remove the
bundled copy and use the system libjs-jquery package instead.

Reference:
  https://security-tracker.debian.org/tracker/CVE-2020-11022
  https://github.com/advisories/GHSA-gxr4-xjj5-5px2

Found by: Attack of the Clones GSoC 2026 pipeline
  (salsa.debian.org/rouca/gsoc2026)

Gajendra Nath Soren

Reply via email to