CVE-2021-41183
published 2021-10-26CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from…
PriorityP335medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
7.95%
94.1th percentile
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jqueryui | < jqueryui 1.13.0+dfsg-1 (bookworm) | jqueryui 1.13.0+dfsg-1 (bookworm) |
| debian | otrs2 | < jqueryui 1.13.0+dfsg-1 (bookworm) | jqueryui 1.13.0+dfsg-1 (bookworm) |
| drupal | drupal | >= 7.0 < 7.86 | 7.86 |
| drupal | drupal | >= 9.2.0 < 9.2.11 | 9.2.11 |
| drupal | drupal | >= 9.3.0 < 9.3.3 | 9.3.3 |
| drupal | drupal_core | — | — |
| drupal | jquery_ui_datepicker | — | — |
| drupal | jquery_ui_datepicker | >= 0 < 1.2.0 | 1.2.0 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jquery | jquery-ui | < 1.13.0 | 1.13.0 |
| jquery | jquery-ui | >= 0 < 1.13.0 | 1.13.0 |
| jqueryui | jquery_ui | < 1.13.0 | 1.13.0 |
| oracle | agile_plm | — | — |
| oracle | application_express | < 22.1.1 | 22.1.1 |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | big_data_spatial_and_graph | < 23.1 | 23.1 |
| oracle | big_data_spatial_and_graph | — | — |
| oracle | communications_interactive_session_recorder | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_oracle6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
jQuery UI vulnerabilities
vendor_ubuntu·2023-10-05·CVSS 6.1
CVE-2021-41183 [MEDIUM] jQuery UI vulnerabilities
Title: jQuery UI vulnerabilities
Summary: Several security issues were fixed in jQuery UI.
Hong Phat Ly discovered that jQuery UI did not properly manage parameters
from untrusted sources, which could lead to arbitrary web script or HTML
code injection. A remote attacker could possibly use this issue to perform
a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)
Esben Sparre Andreasen discovered that jQuery UI did not properly handle
values from untrusted sources in the Datepicker widget. A remote attacker
could possibly use this issue to perform a cross-site scripting (XSS)
attack and execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-4118
Oracle
Oracle Oracle Analytics Risk Matrix: Service Administration UI, BI Platform Security (jQueryUI) — CVE-2021-41183
vendor_oracle·2023-07-15·CVSS 6.1
CVE-2021-41183 [MEDIUM] Oracle Oracle Analytics Risk Matrix: Service Administration UI, BI Platform Security (jQueryUI) — CVE-2021-41183
Oracle Oracle Analytics Risk Matrix: Service Administration UI, BI Platform Security (jQueryUI) vulnerability
CVE: CVE-2021-41183
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Vision (jQueryUI) — CVE-2021-41183
vendor_oracle·2023-04-15·CVSS 6.1
CVE-2021-41183 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Vision (jQueryUI) — CVE-2021-41183
Oracle Oracle Communications Applications Risk Matrix: Vision (jQueryUI) vulnerability
CVE: CVE-2021-41183
CVSS: 6.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Drupal
jQuery UI Datepicker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-004
vendor_drupal·2022-01-19·CVSS 6.5
CVE-2021-41182 [MEDIUM] jQuery UI Datepicker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-004
Title: jQuery UI Datepicker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2022-004
Vulnerability Type: Cross Site Scripting
Description: jQuery UI is a third-party library used by Drupal. The jQuery UI Datepicker module provides the jQuery UI Datepicker library, which is not included in Drupal 9 core. jQuery UI was previously thought to be end-of-life. Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issues that may affect site using the jQuery UI Datepicker module: CVE-2021-41182: XSS in the altField option of the Datepicker widget CVE-2021-41183: XSS in *Text options of the Datepicker widget
Solution: Install the latest version: If you u
Drupal
Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002
vendor_drupal·2022-01-19·CVSS 6.1
CVE-2021-41182 [MEDIUM] Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002
Title: Drupal core - Moderately critical - Cross site scripting - SA-CORE-2022-002
Vulnerability Type: Cross site scripting
Description: jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life. Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. In addition to the issue covered by SA-CORE-2022-001 , further security vulnerabilities disclosed in jQuery UI 1.13.0 may affect Drupal 7 only: CVE-2021-41182: XSS in the altField option of the Datepicker widget CVE-2021-41183: XSS in *Text options of the Datepicker widget Furthermore, other vulnerabilities listed below were previously unaddressed in the version of jQuery UI included in Drupal 7 or in the jQuery Update module: CVE-20
Red Hat
jquery-ui: XSS in *Text options of the datepicker widget
vendor_redhat·2021-10-25·CVSS 6.5
CVE-2021-41183 [MEDIUM] CWE-79 jquery-ui: XSS in *Text options of the datepicker widget
jquery-ui: XSS in *Text options of the datepicker widget
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
Package: jquery-ui (Red Hat Ansible Tower 3) - Not affected
Package: jquery-ui (Red Hat Decision Manager 7) - Out of support scope
Package: pcs (Red Hat Enterprise Linux 6) - Not affected
Package: pcs (Red Hat Enterprise Linux 7) - Not affected
Package: pcs (Red Hat Enterprise Linux 8) - Not affected
Package: j
Debian
CVE-2021-41183: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0...
vendor_debian·2021·CVSS 6.5
CVE-2021-41183 [MEDIUM] CVE-2021-41183: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0...
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
Scope: local
bookworm: resolved (fixed in 1.13.0+dfsg-1)
bullseye: resolved (fixed in 1.12.1+dfsg-8+deb11u1)
forky: resolved (fixed in 1.13.0+dfsg-1)
sid: resolved (fixed in 1.13.0+dfsg-1)
trixie: resolved (fixed in 1.13.0+dfsg-1)
OSV
jqueryui vulnerabilities
osv·2023-10-05·CVSS 6.1
CVE-2016-7103 [MEDIUM] jqueryui vulnerabilities
jqueryui vulnerabilities
Hong Phat Ly discovered that jQuery UI did not properly manage parameters
from untrusted sources, which could lead to arbitrary web script or HTML
code injection. A remote attacker could possibly use this issue to perform
a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)
Esben Sparre Andreasen discovered that jQuery UI did not properly handle
values from untrusted sources in the Datepicker widget. A remote attacker
could possibly use this issue to perform a cross-site scripting (XSS)
attack and execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-41182, CVE-2021-41183)
It was discovered that jQuery UI did not proper
OSV
jQuery UI is a third-party library used by Drupal
osv·2022-01-19·CVSS 6.1
[MEDIUM] jQuery UI is a third-party library used by Drupal
jQuery UI is a third-party library used by Drupal. The jQuery UI Datepicker module provides the jQuery UI Datepicker library, which is not included in Drupal 9 core.
jQuery UI was previously thought to be end-of-life.
Late in 2021, jQuery UI announced that they would be continuing development, and released a [jQuery UI 1.13.0](https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/) version. As part of this 1.13.0 update, they disclosed the following security issues that may affect site using the jQuery UI Datepicker module:
* CVE-2021-41182: [XSS in the altField option of the Datepicker widget](https://github.com/jquery/jquery-ui/security/advisories/GHSA-9gj3-hwp5-pmwc)
* CVE-2021-41183: [XSS in \*Text options of the Datepicker widget](https://github.com/jquery/jquery-ui/security/
GHSA
XSS in `*Text` options of the Datepicker widget in jquery-ui
ghsa·2021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 XSS in `*Text` options of the Datepicker widget in jquery-ui
XSS in `*Text` options of the Datepicker widget in jquery-ui
### Impact
Accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the following way:
```js
$( "#datepicker" ).datepicker( {
showButtonPanel: true,
showOn: "both",
closeText: "doEvilThing( 'closeText XSS' )",
currentText: "doEvilThing( 'currentText XSS' )",
prevText: "doEvilThing( 'prevText XSS' )",
nextText: "doEvilThing( 'nextText XSS' )",
buttonText: "doEvilThing( 'buttonText XSS' )",
appendText: "doEvilThing( 'appendText XSS' )",
} );
```
will call `doEvilThing` with 6 different parameters coming from all `*Text` options.
### Patches
The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` optio
OSV
CVE-2021-41183: jQuery-UI is the official jQuery user interface library
osv·2021-10-26·CVSS 6.1
CVE-2021-41183 [MEDIUM] CVE-2021-41183: jQuery-UI is the official jQuery user interface library
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
OSV
XSS in `*Text` options of the Datepicker widget in jquery-ui
osv·2021-10-26
CVE-2021-41183 [MEDIUM] XSS in `*Text` options of the Datepicker widget in jquery-ui
XSS in `*Text` options of the Datepicker widget in jquery-ui
### Impact
Accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. For example, initializing the datepicker in the following way:
```js
$( "#datepicker" ).datepicker( {
showButtonPanel: true,
showOn: "both",
closeText: "doEvilThing( 'closeText XSS' )",
currentText: "doEvilThing( 'currentText XSS' )",
prevText: "doEvilThing( 'prevText XSS' )",
nextText: "doEvilThing( 'nextText XSS' )",
buttonText: "doEvilThing( 'buttonText XSS' )",
appendText: "doEvilThing( 'appendText XSS' )",
} );
```
will call `doEvilThing` with 6 different parameters coming from all `*Text` options.
### Patches
The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` optio
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/https://bugs.jqueryui.com/ticket/15284https://github.com/jquery/jquery-ui/pull/1953https://github.com/jquery/jquery-ui/security/advisories/GHSA-j7qv-pgf6-hvh4https://lists.debian.org/debian-lts-announce/2022/01/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/https://security.netapp.com/advisory/ntap-20211118-0004/https://www.drupal.org/sa-contrib-2022-004https://www.drupal.org/sa-core-2022-001https://www.drupal.org/sa-core-2022-002https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.tenable.com/security/tns-2022-09https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/https://bugs.jqueryui.com/ticket/15284https://github.com/jquery/jquery-ui/pull/1953https://github.com/jquery/jquery-ui/security/advisories/GHSA-j7qv-pgf6-hvh4https://lists.debian.org/debian-lts-announce/2022/01/msg00014.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/https://security.netapp.com/advisory/ntap-20211118-0004/https://www.drupal.org/sa-contrib-2022-004https://www.drupal.org/sa-core-2022-001https://www.drupal.org/sa-core-2022-002https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.tenable.com/security/tns-2022-09
2021-10-26
Published