CVE-2021-41182
26.10.2021, 15:15
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.
Vendor | Product | Version |
---|---|---|
jqueryui | jquery_ui | 𝑥 < 1.13.0 |
netapp | h500s_firmware | - |
netapp | h700s_firmware | - |
netapp | h300e_firmware | - |
netapp | h500e_firmware | - |
netapp | h700e_firmware | - |
netapp | h410s_firmware | - |
netapp | h410c_firmware | - |
netapp | h300s_firmware | - |
debian | debian_linux | 9.0 |
drupal | drupal | 7.0 ≤ 𝑥 < 7.86 |
oracle | communications_interactive_session_recorder | 6.4 |
oracle | communications_operations_monitor | 4.3 |
oracle | communications_operations_monitor | 4.4 |
oracle | communications_operations_monitor | 5.0 |
oracle | hospitality_suite8 | 8.11.0 ≤ 𝑥 ≤ 8.14.0 |
oracle | hospitality_suite8 | 8.10.2 |
oracle | mysql_enterprise_monitor | 𝑥 ≤ 8.0.29 |
oracle | primavera_unifier | 17.7 |
oracle | primavera_unifier | 17.8 |
oracle | primavera_unifier | 17.9 |
oracle | primavera_unifier | 17.10 |
oracle | primavera_unifier | 17.11 |
oracle | primavera_unifier | 17.12 |
oracle | primavera_unifier | 18.8 |
oracle | primavera_unifier | 19.12 |
oracle | primavera_unifier | 20.12 |
oracle | primavera_unifier | 21.12 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
tenable | tenable.sc | 𝑥 < 5.21.0 |
oracle | agile_plm | 9.3.6 |
oracle | application_express | 𝑥 < 22.1.1 |
oracle | banking_platform | 2.9.0 |
oracle | banking_platform | 2.12.0 |
oracle | big_data_spatial_and_graph | 𝑥 < 23.1 |
oracle | big_data_spatial_and_graph | 23.1 |
oracle | communications_interactive_session_recorder | 6.4 |
oracle | communications_operations_monitor | 4.3 |
oracle | communications_operations_monitor | 4.4 |
oracle | communications_operations_monitor | 5.0 |
oracle | hospitality_inventory_management | 9.1.0 |
oracle | hospitality_materials_control | 18.1 |
oracle | hospitality_suite8 | 8.11.0 ≤ 𝑥 ≤ 8.14.0 |
oracle | hospitality_suite8 | 8.10.2 |
oracle | jd_edwards_enterpriseone_tools | 𝑥 ≤ 9.2.6.3 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | peoplesoft_enterprise_peopletools | 8.59 |
oracle | policy_automation | 12.2.0 ≤ 𝑥 ≤ 12.2.25 |
oracle | primavera_unifier | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_unifier | 18.8 |
oracle | primavera_unifier | 19.12 |
oracle | primavera_unifier | 20.12 |
oracle | primavera_unifier | 21.12 |
oracle | rest_data_services | 𝑥 < 22.1.1 |
oracle | rest_data_services | 22.1.1 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
jqueryui |
|
References