Package: nzbget
Version: 21.0+dfsg-4
Severity: important
Tags: security
X-Debbugs-Cc: [email protected], [email protected]

The NZBGet web interface ships a bundled copy of jQuery at:
  webui/lib/jquery.js

This version is below 3.5.0 and is vulnerable to XSS via DOM
manipulation methods (CVE-2020-11022, CVE-2020-11023). Since NZBGet
actively serves this file to users via its web UI, the XSS
vulnerability is directly exploitable.

Please update the bundled jQuery to 3.5.0 or later, or use the
system libjs-jquery package instead.

Reference:
  https://security-tracker.debian.org/tracker/CVE-2020-11022

Found by: Attack of the Clones GSoC 2026 pipeline
  (salsa.debian.org/rouca/gsoc2026)

Gajendra

Reply via email to