forwarded #1145369 https://github.com/znc/znc/issues/2040
thanks

Am 24.08.2026 um 15:48 schrieb Gajendra Nath Soren:
Package: znc
Version: 1.10.2-1
Severity: important
Tags: security
X-Debbugs-Cc: [email protected], [email protected]

The ZNC web interface ships a bundled copy of jQuery 1.11.2 at:
  webskins/_default_/pub/jquery-1.11.2.js

This version is vulnerable to XSS via DOM manipulation methods
(CVE-2020-11022, CVE-2020-11023, fixed in jQuery 3.5.0). Since ZNC
actively serves this file to users via its web interface, the XSS
vulnerability is exploitable via the ZNC web UI.

Please update the bundled jQuery to 3.5.0 or later, or remove the
bundled copy and use the system libjs-jquery package instead.

Reference:
https://security-tracker.debian.org/tracker/CVE-2020-11022
https://github.com/advisories/GHSA-gxr4-xjj5-5px2

Found by: Attack of the Clones GSoC 2026 pipeline
  (salsa.debian.org/rouca/gsoc2026 <http://salsa.debian.org/rouca/gsoc2026>)

Gajendra Nath Soren

Reply via email to