Описание
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of
option of the .position()
util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the of
option is now treated as a CSS selector. A workaround is to not accept the value of the of
option from untrusted sources.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Tower 3 | jquery-ui | Not affected | ||
Red Hat Decision Manager 7 | jquery-ui | Out of support scope | ||
Red Hat Enterprise Linux 6 | pcs | Not affected | ||
Red Hat Enterprise Linux 7 | pcs | Not affected | ||
Red Hat Enterprise Linux 8 | pcs | Not affected | ||
Red Hat Process Automation 7 | jquery-ui | Out of support scope | ||
Red Hat Virtualization Engine 4.4 | org.ovirt.engine-root | Fixed | RHSA-2022:4711 | 26.05.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
jQuery-UI is the official jQuery user interface library. Prior to vers ...
XSS in the `of` option of the `.position()` util in jquery-ui
Уязвимость метода .position() библиотеки jQuery UI, позволяющая нарушителю выполнить произвольный код
EPSS
6.5 Medium
CVSS3