CVE-2021-41182
published 2021-10-26CVE-2021-41182: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from…
PriorityP342medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
42.23%
98.5th percentile
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jqueryui | < jqueryui 1.13.0+dfsg-1 (bookworm) | jqueryui 1.13.0+dfsg-1 (bookworm) |
| debian | otrs2 | < jqueryui 1.13.0+dfsg-1 (bookworm) | jqueryui 1.13.0+dfsg-1 (bookworm) |
| drupal | drupal | >= 7.0 < 7.86 | 7.86 |
| drupal | drupal_core | — | — |
| drupal | jquery_ui_datepicker | — | — |
| drupal | jquery_ui_datepicker | >= 0 < 1.2.0 | 1.2.0 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jquery | jquery-ui | < 1.13.0 | 1.13.0 |
| jquery | jquery-ui | >= 0 < 1.13.0 | 1.13.0 |
| jqueryui | jquery_ui | < 1.13.0 | 1.13.0 |
| msrc | vp9_video_extensions | — | — |
| oracle | agile_plm | — | — |
| oracle | application_express | < 22.1.1 | 22.1.1 |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | big_data_spatial_and_graph | < 23.1 | 23.1 |
| oracle | big_data_spatial_and_graph | — | — |
| oracle | communications_interactive_session_recorder | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_msrc7.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_oracle6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (jQuery) — CVE-2021-41182
vendor_oracle·2024-01-15·CVSS 6.1
CVE-2021-41182 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Internal Operations (jQuery) — CVE-2021-41182
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (jQuery) vulnerability
CVE: CVE-2021-41182
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Ubuntu
jQuery UI vulnerabilities
vendor_ubuntu·2023-10-05·CVSS 6.1
CVE-2021-41183 [MEDIUM] jQuery UI vulnerabilities
Title: jQuery UI vulnerabilities
Summary: Several security issues were fixed in jQuery UI.
Hong Phat Ly discovered that jQuery UI did not properly manage parameters
from untrusted sources, which could lead to arbitrary web script or HTML
code injection. A remote attacker could possibly use this issue to perform
a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)
Esben Sparre Andreasen discovered that jQuery UI did not properly handle
values from untrusted sources in the Datepicker widget. A remote attacker
could possibly use this issue to perform a cross-site scripting (XSS)
attack and execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-4118
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Open UI (jQueryUI) — CVE-2021-41182
vendor_oracle·2022-10-15·CVSS 6.1
CVE-2021-41182 [MEDIUM] Oracle Oracle Siebel CRM Risk Matrix: Open UI (jQueryUI) — CVE-2021-41182
Oracle Oracle Siebel CRM Risk Matrix: Open UI (jQueryUI) vulnerability
CVE: CVE-2021-41182
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: XML Publisher (jQueryUI) — CVE-2021-41182
vendor_oracle·2022-07-15·CVSS 6.1
CVE-2021-41182 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: XML Publisher (jQueryUI) — CVE-2021-41182
Oracle Oracle PeopleSoft Risk Matrix: XML Publisher (jQueryUI) vulnerability
CVE: CVE-2021-41182
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Drupal
jQuery UI Datepicker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-004
vendor_drupal·2022-01-19·CVSS 6.5
CVE-2021-41182 [MEDIUM] jQuery UI Datepicker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-004
Title: jQuery UI Datepicker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-004
Vulnerability Type: Cross Site Scripting
Description: jQuery UI is a third-party library used by Drupal. The jQuery UI Datepicker module provides the jQuery UI Datepicker library, which is not included in Drupal 9 core. jQuery UI was previously thought to be end-of-life. Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issues that may affect site using the jQuery UI Datepicker module: CVE-2021-41182: XSS in the altField option of the Datepicker widget CVE-2021-41183: XSS in *Text options of the Datepicker widget
Solution: Install the latest version: If you u
Drupal
Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002
vendor_drupal·2022-01-19·CVSS 6.1
CVE-2021-41182 [MEDIUM] Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002
Title: Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002
Vulnerability Type: Cross site scripting
Description: jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life. Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. In addition to the issue covered by SA-CORE-2022-001 , further security vulnerabilities disclosed in jQuery UI 1.13.0 may affect Drupal 7 only: CVE-2021-41182: XSS in the altField option of the Datepicker widget CVE-2021-41183: XSS in *Text options of the Datepicker widget Furthermore, other vulnerabilities listed below were previously unaddressed in the version of jQuery UI included in Drupal 7 or in the jQuery Update module: CVE-20
Red Hat
jquery-ui: XSS in the altField option of the datepicker widget
vendor_redhat·2021-10-25·CVSS 6.5
CVE-2021-41182 [MEDIUM] CWE-79 jquery-ui: XSS in the altField option of the datepicker widget
jquery-ui: XSS in the altField option of the datepicker widget
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.
Package: jquery-ui (Red Hat Ansible Tower 3) - Not affected
Package: jquery-ui (Red Hat Decision Manager 7) - Out of support scope
Package: pcs (Red Hat Enterprise Linux 6) - Not affected
Package: pcs (Red Hat Enterprise Linux 7) - Not affected
Package: pcs (Red Hat Enterprise Linux 8) - Not affected
Package: jque
Microsoft
VP9 Video Extensions Remote Code Execution Vulnerability
vendor_msrc·2021-06-08·CVSS 7.8
CVE-2021-31967 [HIGH] VP9 Video Extensions Remote Code Execution Vulnerability
VP9 Video Extensions Remote Code Execution Vulnerability
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers.
My system is in a disconnected environment; is it vulnerable?
Customers using the Microsoft Store for Business and Microsoft Store for Education can get this update through their organizations.
How can I check if the update is installed?
App package versions 1.0.41182.0 and later contain this update.
You can check the package version in PowerShell:
Get-AppxPackage -Name Microsoft.VP9VideoExte
Debian
CVE-2021-41182: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0...
vendor_debian·2021·CVSS 6.5
CVE-2021-41182 [MEDIUM] CVE-2021-41182: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0...
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.
Scope: local
bookworm: resolved (fixed in 1.13.0+dfsg-1)
bullseye: resolved (fixed in 1.12.1+dfsg-8+deb11u1)
forky: resolved (fixed in 1.13.0+dfsg-1)
sid: resolved (fixed in 1.13.0+dfsg-1)
trixie: resolved (fixed in 1.13.0+dfsg-1)
OSV
jqueryui vulnerabilities
osv·2023-10-05·CVSS 6.1
CVE-2016-7103 [MEDIUM] jqueryui vulnerabilities
jqueryui vulnerabilities
Hong Phat Ly discovered that jQuery UI did not properly manage parameters
from untrusted sources, which could lead to arbitrary web script or HTML
code injection. A remote attacker could possibly use this issue to perform
a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)
Esben Sparre Andreasen discovered that jQuery UI did not properly handle
values from untrusted sources in the Datepicker widget. A remote attacker
could possibly use this issue to perform a cross-site scripting (XSS)
attack and execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-41182, CVE-2021-41183)
It was discovered that jQuery UI did not proper
OSV
jQuery UI is a third-party library used by Drupal
osv·2022-01-19·CVSS 6.1
[MEDIUM] jQuery UI is a third-party library used by Drupal
jQuery UI is a third-party library used by Drupal. The jQuery UI Datepicker module provides the jQuery UI Datepicker library, which is not included in Drupal 9 core.
jQuery UI was previously thought to be end-of-life.
Late in 2021, jQuery UI announced that they would be continuing development, and released a [jQuery UI 1.13.0](https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/) version. As part of this 1.13.0 update, they disclosed the following security issues that may affect site using the jQuery UI Datepicker module:
* CVE-2021-41182: [XSS in the altField option of the Datepicker widget](https://github.com/jquery/jquery-ui/security/advisories/GHSA-9gj3-hwp5-pmwc)
* CVE-2021-41183: [XSS in \*Text options of the Datepicker widget](https://github.com/jquery/jquery-ui/security/
OSV
XSS in the `altField` option of the Datepicker widget in jquery-ui
osv·2021-10-26
CVE-2021-41182 [MEDIUM] XSS in the `altField` option of the Datepicker widget in jquery-ui
XSS in the `altField` option of the Datepicker widget in jquery-ui
### Impact
Accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the following way:
```js
$( "#datepicker" ).datepicker( {
altField: "",
} );
```
will call the `doEvilThing` function.
### Patches
The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector.
### Workarounds
A workaround is to not accept the value of the `altField` option from untrusted sources.
### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery UI repo](https://github.com/jquery/jquery-ui/issues). If you don't
GHSA
XSS in the `altField` option of the Datepicker widget in jquery-ui
ghsa·2021-10-26
CVE-2021-41182 [MEDIUM] CWE-79 XSS in the `altField` option of the Datepicker widget in jquery-ui
XSS in the `altField` option of the Datepicker widget in jquery-ui
### Impact
Accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the following way:
```js
$( "#datepicker" ).datepicker( {
altField: "",
} );
```
will call the `doEvilThing` function.
### Patches
The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector.
### Workarounds
A workaround is to not accept the value of the `altField` option from untrusted sources.
### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery UI repo](https://github.com/jquery/jquery-ui/issues). If you don't
OSV
CVE-2021-41182: jQuery-UI is the official jQuery user interface library
osv·2021-10-26·CVSS 6.1
CVE-2021-41182 [MEDIUM] CVE-2021-41182: jQuery-UI is the official jQuery user interface library
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/https://github.com/jquery/jquery-ui/pull/1954/commits/6809ce843e5ac4128108ea4c15cbc100653c2b63https://github.com/jquery/jquery-ui/security/advisories/GHSA-9gj3-hwp5-pmwchttps://lists.debian.org/debian-lts-announce/2022/01/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/https://security.netapp.com/advisory/ntap-20211118-0004/https://www.drupal.org/sa-contrib-2022-004https://www.drupal.org/sa-core-2022-002https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.tenable.com/security/tns-2022-09https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/https://github.com/jquery/jquery-ui/pull/1954/commits/6809ce843e5ac4128108ea4c15cbc100653c2b63https://github.com/jquery/jquery-ui/security/advisories/GHSA-9gj3-hwp5-pmwchttps://lists.debian.org/debian-lts-announce/2022/01/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/https://security.netapp.com/advisory/ntap-20211118-0004/https://www.drupal.org/sa-contrib-2022-004https://www.drupal.org/sa-core-2022-002https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.tenable.com/security/tns-2022-09
2021-10-26
Published