Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-41182

Опубликовано: 25 окт. 2021
Источник: redhat
CVSS3: 6.5
EPSS Средний

Описание

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the altField option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the altField option is now treated as a CSS selector. A workaround is to not accept the value of the altField option from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Tower 3jquery-uiNot affected
Red Hat Decision Manager 7jquery-uiOut of support scope
Red Hat Enterprise Linux 6pcsNot affected
Red Hat Enterprise Linux 7pcsNot affected
Red Hat Enterprise Linux 8pcsNot affected
Red Hat Process Automation 7jquery-uiOut of support scope
Red Hat Virtualization Engine 4.4org.ovirt.engine-rootFixedRHSA-2022:471126.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2019144jquery-ui: XSS in the altField option of the datepicker widget

EPSS

Процентиль: 96%
0.23693
Средний

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

CVSS3: 6.5
nvd
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

CVSS3: 6.5
debian
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to vers ...

CVSS3: 6.5
github
больше 3 лет назад

XSS in the `altField` option of the Datepicker widget in jquery-ui

EPSS

Процентиль: 96%
0.23693
Средний

6.5 Medium

CVSS3