CVE-2022-31160
published 2022-07-20CVE-2022-31160: jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.48%
82.7th percentile
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jqueryui | < jqueryui 1.13.2+dfsg-1 (bookworm) | jqueryui 1.13.2+dfsg-1 (bookworm) |
| drupal | jquery_ui_checkboxradio | — | — |
| drupal | jquery_ui_checkboxradio | — | — |
| drupal | jquery_ui_checkboxradio | — | — |
| drupal | jquery_ui_checkboxradio | — | — |
| drupal | jquery_ui_checkboxradio | — | — |
| drupal | jquery_ui_checkboxradio | >= 0 < 1.4.0 | 1.4.0 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jquery | jquery-ui | < 1.13.2 | 1.13.2 |
| jquery | jquery-ui | >= 0 < 1.13.2 | 1.13.2 |
| jqueryui | jquery_ui | < 1.13.2 | 1.13.2 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Installation (jQueryUI) — CVE-2022-31160
vendor_oracle·2024-10-15·CVSS 6.1
CVE-2022-31160 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Installation (jQueryUI) — CVE-2022-31160
Oracle Oracle Financial Services Applications Risk Matrix: Installation (jQueryUI) vulnerability
CVE: CVE-2022-31160
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle JD Edwards Risk Matrix: Web Runtime SEC (jQueryUI) — CVE-2022-31160
vendor_oracle·2024-07-15·CVSS 6.1
CVE-2022-31160 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: Web Runtime SEC (jQueryUI) — CVE-2022-31160
Oracle Oracle JD Edwards Risk Matrix: Web Runtime SEC (jQueryUI) vulnerability
CVE: CVE-2022-31160
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jQueryUI) — CVE-2022-31160
vendor_oracle·2024-04-15·CVSS 6.1
CVE-2022-31160 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jQueryUI) — CVE-2022-31160
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (jQueryUI) vulnerability
CVE: CVE-2022-31160
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Billing Care (jQueryUI) — CVE-2022-31160
vendor_oracle·2024-01-15·CVSS 6.1
CVE-2022-31160 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Billing Care (jQueryUI) — CVE-2022-31160
Oracle Oracle Communications Applications Risk Matrix: Billing Care (jQueryUI) vulnerability
CVE: CVE-2022-31160
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: User Interface (jQueryUI) — CVE-2022-31160
vendor_oracle·2023-10-15·CVSS 3.5
CVE-2022-31160 [MEDIUM] Oracle Oracle Construction and Engineering Risk Matrix: User Interface (jQueryUI) — CVE-2022-31160
Oracle Oracle Construction and Engineering Risk Matrix: User Interface (jQueryUI) vulnerability
CVE: CVE-2022-31160
CVSS: 3.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Ubuntu
jQuery UI vulnerabilities
vendor_ubuntu·2023-10-05·CVSS 6.1
CVE-2021-41183 [MEDIUM] jQuery UI vulnerabilities
Title: jQuery UI vulnerabilities
Summary: Several security issues were fixed in jQuery UI.
Hong Phat Ly discovered that jQuery UI did not properly manage parameters
from untrusted sources, which could lead to arbitrary web script or HTML
code injection. A remote attacker could possibly use this issue to perform
a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)
Esben Sparre Andreasen discovered that jQuery UI did not properly handle
values from untrusted sources in the Datepicker widget. A remote attacker
could possibly use this issue to perform a cross-site scripting (XSS)
attack and execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-4118
Oracle
Oracle Oracle Siebel CRM Risk Matrix: UI Framework (jQueryUI) — CVE-2022-31160
vendor_oracle·2023-07-15·CVSS 6.1
CVE-2022-31160 [MEDIUM] Oracle Oracle Siebel CRM Risk Matrix: UI Framework (jQueryUI) — CVE-2022-31160
Oracle Oracle Siebel CRM Risk Matrix: UI Framework (jQueryUI) vulnerability
CVE: CVE-2022-31160
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Console (jQueryUI) — CVE-2022-31160
vendor_oracle·2023-04-15·CVSS 3.9
CVE-2022-31160 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Console (jQueryUI) — CVE-2022-31160
Oracle Oracle Fusion Middleware Risk Matrix: Console (jQueryUI) vulnerability
CVE: CVE-2022-31160
CVSS: 3.9
Protocol: HTTP
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2023 (APR 2023)
Ubuntu
jQuery UI vulnerability
vendor_ubuntu·2022-09-09·CVSS 6.5
CVE-2022-31160 [MEDIUM] jQuery UI vulnerability
Title: jQuery UI vulnerability
Summary: Several security issues were fixed in jQuery UI.
It was discovered that jQuery UI did not properly validate the values from
untrusted sources. An attacker could use this vulnerability to cause a crash or
possibly execute arbitrary code. This issue affected only Ubuntu 18.04 ESM and
Ubuntu 20.4 ESM. (CVE-2021-41184)
It was discovered that jQuery UI checkboxradio widget did not properly decode
certain values from HTML entities. An attacker could possibly use this issue to
generate a cross-site scripting(XSS) attack, resulting in a crash or possibly
execute arbitrary code. (CVE-2022-31160)
Instructions: In general, a standard system update will make all the necessary changes.
Drupal
jQuery UI Checkboxradio - Moderately critical - Cross site scripting - SA-CONTRIB-2022-052
vendor_drupal·2022-08-10·CVSS 6.1
CVE-2022-31160 [MEDIUM] jQuery UI Checkboxradio - Moderately critical - Cross site scripting - SA-CONTRIB-2022-052
Title: jQuery UI Checkboxradio - Moderately critical - Cross site scripting - SA-CONTRIB-2022-052
Vulnerability Type: Cross site scripting
Description: jQuery UI is a third-party library used by Drupal. The jQuery UI Checkboxradio module provides the jQuery UI Checkboxradio library (which was previously in Drupal 8 core, but has since been removed from core and moved to this module). As part of the jQuery UI 1.13.2 update, the jQuery UI project disclosed following security issue that may affect sites using the jQuery UI Checkboxradio module: CVE-2022-31160: XSS when refreshing a checkboxradio with an HTML-like initial text label
Solution: Install the latest version. If you use the jQuery UI Checkboxradio module for Drupal 9, upgrade to: jQuery UI Checkboxradio 8.x-1.4.
Red Hat
jqueryui: XSS when refreshing a checkboxradio with an HTML-like initial text label
vendor_redhat·2022-07-20·CVSS 6.1
CVE-2022-31160 [MEDIUM] CWE-79 jqueryui: XSS when refreshing a checkboxradio with an HTML-like initial text label
jqueryui: XSS when refreshing a checkboxradio with an HTML-like initial text label
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.
A flaw was f
Debian
CVE-2022-31160: jqueryui - jQuery UI is a curated set of user interface interactions, effects, widgets, and...
vendor_debian·2022·CVSS 6.1
CVE-2022-31160 [MEDIUM] CVE-2022-31160: jqueryui - jQuery UI is a curated set of user interface interactions, effects, widgets, and...
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.
Scope: local
bookworm: resolved (fixed in 1.13.2+dfsg-1)
bullseye: resolved (fixed in 1.12.1+dfsg
OSV
jqueryui vulnerabilities
osv·2023-10-05·CVSS 6.1
CVE-2016-7103 [MEDIUM] jqueryui vulnerabilities
jqueryui vulnerabilities
Hong Phat Ly discovered that jQuery UI did not properly manage parameters
from untrusted sources, which could lead to arbitrary web script or HTML
code injection. A remote attacker could possibly use this issue to perform
a cross-site scripting (XSS) attack. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)
Esben Sparre Andreasen discovered that jQuery UI did not properly handle
values from untrusted sources in the Datepicker widget. A remote attacker
could possibly use this issue to perform a cross-site scripting (XSS)
attack and execute arbitrary code. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-41182, CVE-2021-41183)
It was discovered that jQuery UI did not proper
OSV
jqueryui vulnerability
osv·2022-09-09·CVSS 6.1
CVE-2021-41184 [MEDIUM] jqueryui vulnerability
jqueryui vulnerability
It was discovered that jQuery UI did not properly validate the values from
untrusted sources. An attacker could use this vulnerability to cause a crash or
possibly execute arbitrary code. This issue affected only Ubuntu 18.04 ESM and
Ubuntu 20.4 ESM. (CVE-2021-41184)
It was discovered that jQuery UI checkboxradio widget did not properly decode
certain values from HTML entities. An attacker could possibly use this issue to
generate a cross-site scripting(XSS) attack, resulting in a crash or possibly
execute arbitrary code. (CVE-2022-31160)
OSV
CVE-2022-31160: jQuery UI is a third-party library used by Drupal
osv·2022-08-10·CVSS 6.1
CVE-2022-31160 [MEDIUM] CVE-2022-31160: jQuery UI is a third-party library used by Drupal
jQuery UI is a third-party library used by Drupal. The jQuery UI Checkboxradio module provides the jQuery UI Checkboxradio library (which was previously in Drupal 8 core, but has since been removed from core and moved to this module).
As part of the jQuery UI 1.13.2 update, the jQuery UI project disclosed following security issue that may affect sites using the jQuery UI Checkboxradio module:
* CVE-2022-31160: [XSS when refreshing a checkboxradio with an HTML-like initial text label](https://github.com/jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9)
OSV
CVE-2022-31160: jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery
osv·2022-07-20·CVSS 6.1
CVE-2022-31160 [MEDIUM] CVE-2022-31160: jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.
GHSA
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
ghsa·2022-07-18
CVE-2022-31160 [MEDIUM] CWE-79 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
### Impact
Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. If you call `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities, they will erroneously get decoded. This can lead to potentially executing JavaScript code.
For example, starting with the following initial secure HTML:
```html
```
and calling:
```js
$( "#test-input" ).checkboxradio();
$( "#test-input" ).checkboxradio( "refresh" );
```
will turn the initial HTML into:
```html
```
and the alert will get executed.
### Patches
The bug has been patched in jQuery UI 1.13.2.
### Workarounds
To reme
OSV
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
osv·2022-07-18
CVE-2022-31160 [MEDIUM] jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
### Impact
Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. If you call `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities, they will erroneously get decoded. This can lead to potentially executing JavaScript code.
For example, starting with the following initial secure HTML:
```html
```
and calling:
```js
$( "#test-input" ).checkboxradio();
$( "#test-input" ).checkboxradio( "refresh" );
```
will turn the initial HTML into:
```html
```
and the alert will get executed.
### Patches
The bug has been patched in jQuery UI 1.13.2.
### Workarounds
To reme
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.jqueryui.com/2022/07/jquery-ui-1-13-2-released/https://github.com/jquery/jquery-ui/commit/8cc5bae1caa1fcf96bf5862c5646c787020ba3f9https://github.com/jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9https://lists.debian.org/debian-lts-announce/2022/12/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XBR3G3JR5ZIOJDO4224M3INXDS2VFDD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J5LGNTICB5BRFAG3DHVVELS6H3CZSQMO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QB2FJQXCNHO32VGVOC6DY6IPGVE4VDU6/https://security.netapp.com/advisory/ntap-20220909-0007/https://www.drupal.org/sa-contrib-2022-052https://blog.jqueryui.com/2022/07/jquery-ui-1-13-2-released/https://github.com/jquery/jquery-ui/commit/8cc5bae1caa1fcf96bf5862c5646c787020ba3f9https://github.com/jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9https://lists.debian.org/debian-lts-announce/2022/12/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XBR3G3JR5ZIOJDO4224M3INXDS2VFDD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J5LGNTICB5BRFAG3DHVVELS6H3CZSQMO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QB2FJQXCNHO32VGVOC6DY6IPGVE4VDU6/https://security.netapp.com/advisory/ntap-20220909-0007/https://www.drupal.org/sa-contrib-2022-052
2022-07-20
Published