ARC25-001

CISA KEV jQuery Cross-Site Scripting (XSS) Vulnerability (CVE-2020-11023) - Arctera

Revision History

  • 1.0: January 29, 2025: Initial version
  • 1.1: February 14, 2025: Added Vulnerability Assessment

Summary

Arctera is aware of the jQuery Cross-Site Scripting (XSS) Vulnerability (CVE-2020-11023) which was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on January 23, 2025. All Arctera Product Security and Development teams have completed reviewing our software to determine if the vulnerability exists in our products. We have assessed that no currently supported Arctera products are exploitable to this vulnerability.

The following Arctera products were found to include vulnerable jQuery components:

  • Backup Exec
    • Backup Exec 23.0 and newer do not contain the vulnerable jQuery component.
    • Backup Exec 22.0 and older do use the vulnerable versions of jQuery.
      • However, Backup Exec uses jQuery only during Installing the product and only uses it to extract certain information from our own trusted DVD Image. It is not subject to or acts upon any data from external or untrusted sources. Therefore, the vulnerability has been assessed to be non-exploitable in any supported Backup Exec product.
  • InfoScale
    • The “HA Plugin wizard’ included in supported versions of InfoScale included vulnerable versions of the jQuery component.
      • However, these Apache Flex based wizards became non-functional in December 2020 when browsers removed support for Adobe Flash. Therefore, the vulnerability has been assessed to be non-exploitable in any supported InfoScale product.

Questions

For questions or problems regarding these vulnerabilities please contact Arctera Technical Support (https://www.arctera.io/support).

Disclaimer

THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. ARCTERA US LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.

Arctera US LLC
6200 Stoneridge Mall Road, Suite 150
Pleasanton, CA 94588