CVE-2021-41183

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
GitHub_MCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
VendorProductVersion
jqueryuijquery_ui
𝑥
< 1.13.0
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph300e_firmware
-
netapph500e_firmware
-
netapph700e_firmware
-
netapph410s_firmware
-
netapph410c_firmware
-
debiandebian_linux
9.0
drupaldrupal
7.0 ≤
𝑥
< 7.86
drupaldrupal
9.2.0 ≤
𝑥
< 9.2.11
drupaldrupal
9.3.0 ≤
𝑥
< 9.3.3
oracleagile_plm
9.3.6
oracleapplication_express
𝑥
< 22.1.1
oraclebanking_platform
2.9.0
oraclebanking_platform
2.12.0
oraclebig_data_spatial_and_graph
𝑥
< 23.1
oraclebig_data_spatial_and_graph
23.1
oraclecommunications_interactive_session_recorder
6.4
oraclecommunications_operations_monitor
4.3
oraclecommunications_operations_monitor
4.4
oraclecommunications_operations_monitor
5.0
oraclehospitality_inventory_management
9.1.0
oraclehospitality_suite8
8.11.0 ≤
𝑥
≤ 11.14.0
oraclehospitality_suite8
8.10.2
oraclejd_edwards_enterpriseone_tools
𝑥
≤ 9.2.6.3
oraclemysql_enterprise_monitor
𝑥
≤ 8.0.29
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oraclepolicy_automation
12.2.0 ≤
𝑥
≤ 12.2.5
oracleprimavera_gateway
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_gateway
18.8.0
oracleprimavera_gateway
19.12.0
oracleprimavera_gateway
20.12.0
oracleprimavera_gateway
21.12.0
oraclerest_data_services
𝑥
< 22.1.1
oraclerest_data_services
22.1.1
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
tenabletenable.sc
𝑥
< 5.21.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jqueryui
bullseye
1.12.1+dfsg-8+deb11u2
no-dsa
stretch
no-dsa
bookworm
1.13.2+dfsg-1
fixed
sid
1.13.2+dfsg-1
fixed
trixie
1.13.2+dfsg-1
fixed
otrs2
bullseye/non-free
vulnerable
stretch
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jqueryui
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
not-affected
impish
ignored
hirsute
ignored
focal
Fixed 1.12.1+dfsg-5ubuntu0.20.04.1
released
bionic
Fixed 1.12.1+dfsg-5ubuntu0.18.04.1~esm3
released
xenial
Fixed 1.10.1+dfsg-1ubuntu0.16.04.1~esm1
released
trusty
Fixed 1.10.1+dfsg-1ubuntu0.14.04.1~esm1
released
References