CVE-2021-41184
medium · 6.5jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
6.5
CVSS
40.8%
EPSS (exploit prob.)
99th
EPSS percentile
2021-10-26
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| jqueryui | jquery_ui | < 1.13.0 |
| fedoraproject | fedora | 33 |
| fedoraproject | fedora | 34 |
| fedoraproject | fedora | 35 |
| fedoraproject | fedora | 36 |
| netapp | h300s_firmware | all versions |
| netapp | h300s | all versions |
| netapp | h500s_firmware | all versions |
| netapp | h500s | all versions |
| netapp | h700s_firmware | all versions |
| netapp | h700s | all versions |
| netapp | h300e_firmware | all versions |
| netapp | h300e | all versions |
| netapp | h500e_firmware | all versions |
| netapp | h500e | all versions |
| netapp | h700e_firmware | all versions |
| netapp | h700e | all versions |
| netapp | h410s_firmware | all versions |
| netapp | h410s | all versions |
| netapp | h410c_firmware | all versions |
| netapp | h410c | all versions |
| drupal | drupal | >= 7.0, < 7.86 |
| drupal | drupal | >= 9.2.0, < 9.2.11 |
| drupal | drupal | >= 9.3.0, < 9.3.3 |
| tenable | tenable.sc | < 5.21.0 |
| oracle | agile_product_lifecycle_management | 9.3.6 |
| oracle | application_express | < 22.1.1 |
| oracle | banking_platform | 2.9.0 |
| oracle | banking_platform | 2.12.0 |
| oracle | big_data_spatial_and_graph | < 23.1 |
| oracle | big_data_spatial_and_graph | 23.1 |
| oracle | communications_interactive_session_recorder | 6.4 |
| oracle | communications_operations_monitor | 4.3 |
| oracle | communications_operations_monitor | 4.4 |
| oracle | communications_operations_monitor | 5.0 |
| oracle | hospitality_inventory_management | 9.1.0 |
| oracle | hospitality_materials_control | 18.1 |
| oracle | hospitality_suite8 | >= 8.11.0, <= 8.14.0 |
| oracle | hospitality_suite8 | 8.10.2 |
| oracle | jd_edwards_enterpriseone_tools | <= 9.2.6.3 |
Check a specific version with /api/v1/cve/match.
References
- https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/
- https://github.com/jquery/jquery-ui/commit/effa323f1505f2ce7a324e4f429fa9032c72f280
- https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/
- https://security.netapp.com/advisory/ntap-20211118-0004/
- https://www.drupal.org/sa-core-2022-001
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.tenable.com/security/tns-2022-09
- http://seclists.org/fulldisclosure/2024/Aug/37
- https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/
- https://github.com/jquery/jquery-ui/commit/effa323f1505f2ce7a324e4f429fa9032c72f280
- https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/
- https://security.netapp.com/advisory/ntap-20211118-0004/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-41184