CVE-2021-41184

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
GitHub_MCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
jqueryuijquery_ui
𝑥
< 1.13.0
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph300e_firmware
-
netapph500e_firmware
-
netapph700e_firmware
-
netapph410s_firmware
-
netapph410c_firmware
-
drupaldrupal
7.0 ≤
𝑥
< 7.86
drupaldrupal
9.2.0 ≤
𝑥
< 9.2.11
drupaldrupal
9.3.0 ≤
𝑥
< 9.3.3
tenabletenable.sc
𝑥
< 5.21.0
oracleagile_plm
9.3.6
oracleapplication_express
𝑥
< 22.1.1
oraclebanking_platform
2.9.0
oraclebanking_platform
2.12.0
oraclebig_data_spatial_and_graph
𝑥
< 23.1
oraclebig_data_spatial_and_graph
23.1
oraclecommunications_interactive_session_recorder
6.4
oraclecommunications_operations_monitor
4.3
oraclecommunications_operations_monitor
4.4
oraclecommunications_operations_monitor
5.0
oraclehospitality_inventory_management
9.1.0
oraclehospitality_materials_control
18.1
oraclehospitality_suite8
8.11.0 ≤
𝑥
≤ 8.14.0
oraclehospitality_suite8
8.10.2
oraclejd_edwards_enterpriseone_tools
𝑥
≤ 9.2.6.3
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oraclepolicy_automation
12.2.0 ≤
𝑥
≤ 12.2.25
oracleprimavera_unifier
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oracleprimavera_unifier
20.12
oracleprimavera_unifier
21.12
oraclerest_data_services
𝑥
< 22.1.1
oraclerest_data_services
22.1.1
oracleweblogic_server
12.2.1.3.0
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jqueryui
bullseye
1.12.1+dfsg-8+deb11u2
no-dsa
stretch
no-dsa
bookworm
1.13.2+dfsg-1
fixed
sid
1.13.2+dfsg-1
fixed
trixie
1.13.2+dfsg-1
fixed
otrs2
bullseye/non-free
vulnerable
stretch
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jqueryui
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
ignored
hirsute
ignored
focal
Fixed 1.12.1+dfsg-5ubuntu0.20.04.1
released
bionic
Fixed 1.12.1+dfsg-5ubuntu0.18.04.1~esm2
released
xenial
not-affected
trusty
not-affected
References