Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-41184

Опубликовано: 26 окт. 2021
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4.3
CVSS3: 6.5

Описание

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of option of the .position() util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the of option is now treated as a CSS selector. A workaround is to not accept the value of the of option from untrusted sources.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

1.13.0
esm-apps/bionic

released

1.12.1+dfsg-5ubuntu0.18.04.1~esm2
esm-apps/focal

released

1.12.1+dfsg-5ubuntu0.20.04.1
esm-apps/jammy

not-affected

1.13.0
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
focal

released

1.12.1+dfsg-5ubuntu0.20.04.1
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

EPSS

Процентиль: 96%
0.29896
Средний

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
почти 4 года назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

CVSS3: 6.5
nvd
почти 4 года назад

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

CVSS3: 6.5
debian
почти 4 года назад

jQuery-UI is the official jQuery user interface library. Prior to vers ...

CVSS3: 6.5
github
почти 4 года назад

XSS in the `of` option of the `.position()` util in jquery-ui

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость метода .position() библиотеки jQuery UI, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.29896
Средний

4.3 Medium

CVSS2

6.5 Medium

CVSS3