Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-41182

Опубликовано: 26 окт. 2021
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4.3
CVSS3: 6.5

Описание

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the altField option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the altField option is now treated as a CSS selector. A workaround is to not accept the value of the altField option from untrusted sources.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

1.13.2+dfsg-1
esm-apps/bionic

released

1.12.1+dfsg-5ubuntu0.18.04.1~esm3
esm-apps/focal

released

1.12.1+dfsg-5ubuntu0.20.04.1
esm-apps/jammy

not-affected

1.13.1+dfsg-1
esm-apps/xenial

released

1.10.1+dfsg-1ubuntu0.16.04.1~esm1
esm-infra-legacy/trusty

not-affected

1.10.1+dfsg-1ubuntu0.14.04.1~esm1
focal

released

1.12.1+dfsg-5ubuntu0.20.04.1
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

EPSS

Процентиль: 96%
0.23693
Средний

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

CVSS3: 6.5
nvd
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

CVSS3: 6.5
debian
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to vers ...

CVSS3: 6.5
github
больше 3 лет назад

XSS in the `altField` option of the Datepicker widget in jquery-ui

EPSS

Процентиль: 96%
0.23693
Средний

4.3 Medium

CVSS2

6.5 Medium

CVSS3