CVE-2021-41184
published 2021-10-26CVE-2021-41184: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from…
PriorityP343medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
44.52%
98.6th percentile
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jqueryui | < jqueryui 1.13.0+dfsg-1 (bookworm) | jqueryui 1.13.0+dfsg-1 (bookworm) |
| debian | otrs2 | < jqueryui 1.13.0+dfsg-1 (bookworm) | jqueryui 1.13.0+dfsg-1 (bookworm) |
| drupal | core | >= 8.0.0 < 9.2.11 | 9.2.11 |
| drupal | core | >= 9.3.0 < 9.3.3 | 9.3.3 |
| drupal | drupal | >= 7.0 < 7.86 | 7.86 |
| drupal | drupal | >= 9.2.0 < 9.2.11 | 9.2.11 |
| drupal | drupal | >= 9.3.0 < 9.3.3 | 9.3.3 |
| drupal | drupal_core | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jquery | jquery-ui | < 1.13.0 | 1.13.0 |
| jquery | jquery-ui | >= 0 < 1.13.0 | 1.13.0 |
| jqueryui | jquery_ui | < 1.13.0 | 1.13.0 |
| oracle | agile_plm | — | — |
| oracle | application_express | < 22.1.1 | 22.1.1 |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | big_data_spatial_and_graph | < 23.1 | 23.1 |
| oracle | big_data_spatial_and_graph | — | — |
| oracle | communications_interactive_session_recorder | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_oracle6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle GoldenGate Risk Matrix: Embedded Web UI for Services (jQueryUI) — CVE-2021-41184
vendor_oracle·2025-04-15·CVSS 4.0
CVE-2021-41184 [MEDIUM] Oracle Oracle GoldenGate Risk Matrix: Embedded Web UI for Services (jQueryUI) — CVE-2021-41184
Oracle Oracle GoldenGate Risk Matrix: Embedded Web UI for Services (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 4.0
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (jQueryUI) — CVE-2021-41184
vendor_oracle·2024-10-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Utilities Applications Risk Matrix: General (jQueryUI) — CVE-2021-41184
Oracle Oracle Utilities Applications Risk Matrix: General (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Security (jQueryUI) — CVE-2021-41184
vendor_oracle·2024-07-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Communications Risk Matrix: Security (jQueryUI) — CVE-2021-41184
Oracle Oracle Communications Risk Matrix: Security (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Ubuntu
jQuery UI vulnerabilities
vendor_ubuntu·2023-10-05·CVSS 6.1
CVE-2021-41183 [MEDIUM] jQuery UI vulnerabilities
Title: jQuery UI vulnerabilities
Summary: Several security issues were fixed in jQuery UI.
Hong Phat Ly discovered that jQuery UI did not properly manage parameters
from untrusted sources, which could lead to arbitrary web script or HTML
code injection. A remote attacker could possibly use this issue to perform
a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)
Esben Sparre Andreasen discovered that jQuery UI did not properly handle
values from untrusted sources in the Datepicker widget. A remote attacker
could possibly use this issue to perform a cross-site scripting (XSS)
attack and execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-4118
Oracle
Oracle Oracle Commerce Risk Matrix: Experience Manager (jQueryUI) — CVE-2021-41184
vendor_oracle·2023-07-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Experience Manager (jQueryUI) — CVE-2021-41184
Oracle Oracle Commerce Risk Matrix: Experience Manager (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jQueryUI) — CVE-2021-41184
vendor_oracle·2023-04-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jQueryUI) — CVE-2021-41184
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Engagement (jQuery UI) — CVE-2021-41184
vendor_oracle·2023-01-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Food and Beverage Applications Risk Matrix: Engagement (jQuery UI) — CVE-2021-41184
Oracle Oracle Food and Beverage Applications Risk Matrix: Engagement (jQuery UI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Management (jQueryUI) — CVE-2021-41184
vendor_oracle·2022-10-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Communications Risk Matrix: Management (jQueryUI) — CVE-2021-41184
Oracle Oracle Communications Risk Matrix: Management (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Ubuntu
jQuery UI vulnerability
vendor_ubuntu·2022-09-09·CVSS 6.5
CVE-2022-31160 [MEDIUM] jQuery UI vulnerability
Title: jQuery UI vulnerability
Summary: Several security issues were fixed in jQuery UI.
It was discovered that jQuery UI did not properly validate the values from
untrusted sources. An attacker could use this vulnerability to cause a crash or
possibly execute arbitrary code. This issue affected only Ubuntu 18.04 ESM and
Ubuntu 20.4 ESM. (CVE-2021-41184)
It was discovered that jQuery UI checkboxradio widget did not properly decode
certain values from HTML entities. An attacker could possibly use this issue to
generate a cross-site scripting(XSS) attack, resulting in a crash or possibly
execute arbitrary code. (CVE-2022-31160)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (jQueryUI) — CVE-2021-41184
vendor_oracle·2022-07-15·CVSS 5.4
CVE-2021-41184 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Application Express (jQueryUI) — CVE-2021-41184
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Dashboard (jQueryUI) — CVE-2021-41184
vendor_oracle·2022-04-15·CVSS 6.1
CVE-2021-41184 [MEDIUM] Oracle Oracle Communications Risk Matrix: Dashboard (jQueryUI) — CVE-2021-41184
Oracle Oracle Communications Risk Matrix: Dashboard (jQueryUI) vulnerability
CVE: CVE-2021-41184
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Drupal
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2022-001
vendor_drupal·2022-01-19·CVSS 6.5
CVE-2021-41184 [MEDIUM] Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2022-001
Title: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2022-001
Vulnerability Type: Cross Site Scripting
Description: jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life. Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issue that may affect Drupal 9 and 7: CVE-2021-41184: XSS in the `of` option of the `.position()` util It is possible that this vulnerability is exploitable with some Drupal modules. As a precaution, this Drupal security release applies the fix for the above cross-site description issue, without making any of the other changes to the jQuery version that is included
Red Hat
jquery-ui: XSS in the 'of' option of the .position() util
vendor_redhat·2021-10-25·CVSS 6.5
CVE-2021-41184 [MEDIUM] CWE-79 jquery-ui: XSS in the 'of' option of the .position() util
jquery-ui: XSS in the 'of' option of the .position() util
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
Package: jquery-ui (Red Hat Ansible Tower 3) - Not affected
Package: jquery-ui (Red Hat Decision Manager 7) - Out of support scope
Package: pcs (Red Hat Enterprise Linux 6) - Not affected
Package: pcs (Red Hat Enterprise Linux 7) - Not affected
Package: pcs (Red Hat Enterprise Linux 8) - Not affected
Package: jquery-ui (Red Hat Process
Debian
CVE-2021-41184: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0...
vendor_debian·2021·CVSS 6.5
CVE-2021-41184 [MEDIUM] CVE-2021-41184: jqueryui - jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0...
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
Scope: local
bookworm: resolved (fixed in 1.13.0+dfsg-1)
bullseye: resolved (fixed in 1.12.1+dfsg-8+deb11u1)
forky: resolved (fixed in 1.13.0+dfsg-1)
sid: resolved (fixed in 1.13.0+dfsg-1)
trixie: resolved (fixed in 1.13.0+dfsg-1)
OSV
jqueryui vulnerabilities
osv·2023-10-05·CVSS 6.1
CVE-2016-7103 [MEDIUM] jqueryui vulnerabilities
jqueryui vulnerabilities
Hong Phat Ly discovered that jQuery UI did not properly manage parameters
from untrusted sources, which could lead to arbitrary web script or HTML
code injection. A remote attacker could possibly use this issue to perform
a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)
Esben Sparre Andreasen discovered that jQuery UI did not properly handle
values from untrusted sources in the Datepicker widget. A remote attacker
could possibly use this issue to perform a cross-site scripting (XSS)
attack and execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-41182, CVE-2021-41183)
It was discovered that jQuery UI did not proper
OSV
jqueryui vulnerability
osv·2022-09-09·CVSS 6.1
CVE-2021-41184 [MEDIUM] jqueryui vulnerability
jqueryui vulnerability
It was discovered that jQuery UI did not properly validate the values from
untrusted sources. An attacker could use this vulnerability to cause a crash or
possibly execute arbitrary code. This issue affected only Ubuntu 18.04 ESM and
Ubuntu 20.4 ESM. (CVE-2021-41184)
It was discovered that jQuery UI checkboxradio widget did not properly decode
certain values from HTML entities. An attacker could possibly use this issue to
generate a cross-site scripting(XSS) attack, resulting in a crash or possibly
execute arbitrary code. (CVE-2022-31160)
OSV
CVE-2021-41184: jQuery UI is a third-party library used by Drupal
osv·2022-01-19·CVSS 6.1
CVE-2021-41184 [MEDIUM] CVE-2021-41184: jQuery UI is a third-party library used by Drupal
jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life.
Late in 2021, jQuery UI announced that they would be continuing development, and released a [jQuery UI 1.13.0](https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/) version. As part of this 1.13.0 update, they disclosed the following security issue that may affect Drupal 9 and 7:
* CVE-2021-41184: [XSS in the `of` option of the `.position()` util](https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327)
It is possible that this vulnerability is exploitable with some Drupal modules. As a precaution, this Drupal security release applies the fix for the above cross-site description issue, without making any of the other changes to the jQuery version that is
OSV
CVE-2021-41184: jQuery-UI is the official jQuery user interface library
osv·2021-10-26·CVSS 6.1
CVE-2021-41184 [MEDIUM] CVE-2021-41184: jQuery-UI is the official jQuery user interface library
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
GHSA
XSS in the `of` option of the `.position()` util in jquery-ui
ghsa·2021-10-26
CVE-2021-41184 [MEDIUM] CWE-79 XSS in the `of` option of the `.position()` util in jquery-ui
XSS in the `of` option of the `.position()` util in jquery-ui
### Impact
Accepting the value of the `of` option of the [`.position()`](https://api.jqueryui.com/position/) util from untrusted sources may execute untrusted code. For example, invoking the following code:
```js
$( "#element" ).position( {
my: "left top",
at: "right bottom",
of: "",
collision: "none"
} );
```
will call the `doEvilThing()` function.
### Patches
The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector.
### Workarounds
A workaround is to not accept the value of the `of` option from untrusted sources.
### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery UI repo](https://github.com
OSV
XSS in the `of` option of the `.position()` util in jquery-ui
osv·2021-10-26
CVE-2021-41184 [MEDIUM] XSS in the `of` option of the `.position()` util in jquery-ui
XSS in the `of` option of the `.position()` util in jquery-ui
### Impact
Accepting the value of the `of` option of the [`.position()`](https://api.jqueryui.com/position/) util from untrusted sources may execute untrusted code. For example, invoking the following code:
```js
$( "#element" ).position( {
my: "left top",
at: "right bottom",
of: "",
collision: "none"
} );
```
will call the `doEvilThing()` function.
### Patches
The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector.
### Workarounds
A workaround is to not accept the value of the `of` option from untrusted sources.
### For more information
If you have any questions or comments about this advisory, search for a relevant issue in [the jQuery UI repo](https://github.com
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/https://github.com/jquery/jquery-ui/commit/effa323f1505f2ce7a324e4f429fa9032c72f280https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327https://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/https://security.netapp.com/advisory/ntap-20211118-0004/https://www.drupal.org/sa-core-2022-001https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.tenable.com/security/tns-2022-09http://seclists.org/fulldisclosure/2024/Aug/37https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/https://github.com/jquery/jquery-ui/commit/effa323f1505f2ce7a324e4f429fa9032c72f280https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327https://lists.debian.org/debian-lts-announce/2023/08/msg00040.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXIUUBRVLA4E7G7MMIKCEN75YN7UFERW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O74SXYY7RGXREQDQUDQD4BPJ4QQTD2XQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNXA7XRKGINWSUIPIZ6ZBCTV6N3KSHES/https://security.netapp.com/advisory/ntap-20211118-0004/https://www.drupal.org/sa-core-2022-001https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.tenable.com/security/tns-2022-09
2021-10-26
Published