You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of option of the .position() util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the of option is now treated as a CSS selector. A workaround is to not accept the value of the of option from untrusted sources.
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various *Text options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various *Text options are now always treated as pure text, not HTML. A workaround is to not accept the value of the *Text options from untrusted sources.
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the altField option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the altField option is now treated as a CSS selector. A workaround is to not accept the value of the altField option from untrusted sources.
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
Vulnerable Library - jquery-ui-1.8.19.min.js
A curated set of user interface interactions, effects, widgets, and themes built on top of the jQuery JavaScript Library.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.8.19/jquery-ui.min.js
Path to dependency file: /src/main/webapp/index.jsp
Path to vulnerable library: /src/main/webapp/js/jqueryUI.js,/src/main/webapp/js/jqueryUI.js
Found in HEAD commit: 09549dbf969b19cac284087efeca5acf770cb2bd
Vulnerabilities
Details
CVE-2021-41184
Vulnerable Library - jquery-ui-1.8.19.min.js
A curated set of user interface interactions, effects, widgets, and themes built on top of the jQuery JavaScript Library.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.8.19/jquery-ui.min.js
Path to dependency file: /src/main/webapp/index.jsp
Path to vulnerable library: /src/main/webapp/js/jqueryUI.js,/src/main/webapp/js/jqueryUI.js
Dependency Hierarchy:
Found in HEAD commit: 09549dbf969b19cac284087efeca5acf770cb2bd
Found in base branch: dev
Vulnerability Details
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the
of
option of the.position()
util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to theof
option is now treated as a CSS selector. A workaround is to not accept the value of theof
option from untrusted sources.Publish Date: 2021-10-26
URL: CVE-2021-41184
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41184
Release Date: 2021-10-26
Fix Resolution: jquery-ui - 1.13.0
CVE-2021-41183
Vulnerable Library - jquery-ui-1.8.19.min.js
A curated set of user interface interactions, effects, widgets, and themes built on top of the jQuery JavaScript Library.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.8.19/jquery-ui.min.js
Path to dependency file: /src/main/webapp/index.jsp
Path to vulnerable library: /src/main/webapp/js/jqueryUI.js,/src/main/webapp/js/jqueryUI.js
Dependency Hierarchy:
Found in HEAD commit: 09549dbf969b19cac284087efeca5acf770cb2bd
Found in base branch: dev
Vulnerability Details
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various
*Text
options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various*Text
options are now always treated as pure text, not HTML. A workaround is to not accept the value of the*Text
options from untrusted sources.Publish Date: 2021-10-26
URL: CVE-2021-41183
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41183
Release Date: 2021-10-26
Fix Resolution: jquery-ui - 1.13.0
CVE-2021-41182
Vulnerable Library - jquery-ui-1.8.19.min.js
A curated set of user interface interactions, effects, widgets, and themes built on top of the jQuery JavaScript Library.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.8.19/jquery-ui.min.js
Path to dependency file: /src/main/webapp/index.jsp
Path to vulnerable library: /src/main/webapp/js/jqueryUI.js,/src/main/webapp/js/jqueryUI.js
Dependency Hierarchy:
Found in HEAD commit: 09549dbf969b19cac284087efeca5acf770cb2bd
Found in base branch: dev
Vulnerability Details
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the
altField
option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to thealtField
option is now treated as a CSS selector. A workaround is to not accept the value of thealtField
option from untrusted sources.Publish Date: 2021-10-26
URL: CVE-2021-41182
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41182
Release Date: 2021-10-26
Fix Resolution: jquery-ui - 1.13.0
CVE-2016-7103
Vulnerable Library - jquery-ui-1.8.19.min.js
A curated set of user interface interactions, effects, widgets, and themes built on top of the jQuery JavaScript Library.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.8.19/jquery-ui.min.js
Path to dependency file: /src/main/webapp/index.jsp
Path to vulnerable library: /src/main/webapp/js/jqueryUI.js,/src/main/webapp/js/jqueryUI.js
Dependency Hierarchy:
Found in HEAD commit: 09549dbf969b19cac284087efeca5acf770cb2bd
Found in base branch: dev
Vulnerability Details
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
Publish Date: 2017-03-15
URL: CVE-2016-7103
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7103
Release Date: 2017-03-15
Fix Resolution: jquery-ui - 1.12.0
The text was updated successfully, but these errors were encountered: