Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-41183

Опубликовано: 25 окт. 2021
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various *Text options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various *Text options are now always treated as pure text, not HTML. A workaround is to not accept the value of the *Text options from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Tower 3jquery-uiNot affected
Red Hat Decision Manager 7jquery-uiOut of support scope
Red Hat Enterprise Linux 6pcsNot affected
Red Hat Enterprise Linux 7pcsNot affected
Red Hat Enterprise Linux 8pcsNot affected
Red Hat Process Automation 7jquery-uiOut of support scope
Red Hat Virtualization Engine 4.4org.ovirt.engine-rootFixedRHSA-2022:471126.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2019148jquery-ui: XSS in *Text options of the datepicker widget

EPSS

Процентиль: 81%
0.01668
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.

CVSS3: 6.5
nvd
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.

CVSS3: 6.5
debian
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to vers ...

CVSS3: 6.5
github
больше 3 лет назад

XSS in `*Text` options of the Datepicker widget in jquery-ui

EPSS

Процентиль: 81%
0.01668
Низкий

6.5 Medium

CVSS3