Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-41184

Опубликовано: 26 окт. 2021
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4.3
CVSS3: 6.5

Описание

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of option of the .position() util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the of option is now treated as a CSS selector. A workaround is to not accept the value of the of option from untrusted sources.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

1.13.0
esm-apps/bionic

released

1.12.1+dfsg-5ubuntu0.18.04.1~esm2
esm-apps/focal

released

1.12.1+dfsg-5ubuntu0.20.04.1
esm-apps/jammy

not-affected

1.13.0
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

released

1.12.1+dfsg-5ubuntu0.20.04.1
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

EPSS

Процентиль: 96%
0.2794
Средний

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

CVSS3: 6.5
nvd
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

CVSS3: 6.5
debian
больше 3 лет назад

jQuery-UI is the official jQuery user interface library. Prior to vers ...

CVSS3: 6.5
github
больше 3 лет назад

XSS in the `of` option of the `.position()` util in jquery-ui

CVSS3: 6.5
fstec
около 4 лет назад

Уязвимость метода .position() библиотеки jQuery UI, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.2794
Средний

4.3 Medium

CVSS2

6.5 Medium

CVSS3