Lucene search

K
cve[email protected]CVE-2021-41184
HistoryOct 26, 2021 - 3:15 p.m.

CVE-2021-41184

2021-10-2615:15:10
CWE-79
web.nvd.nist.gov
404
8
jquery-ui
cve-2021-41184
security vulnerability
code execution
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

6.2 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.1%

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of option of the .position() util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the of option is now treated as a CSS selector. A workaround is to not accept the value of the of option from untrusted sources.

Affected configurations

Vulners
NVD
Node
jqueryjqueryRange<1.13.0
VendorProductVersionCPE
jqueryjquery*cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "jquery",
    "product": "jquery-ui",
    "versions": [
      {
        "version": "< 1.13.0",
        "status": "affected"
      }
    ]
  }
]

References

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

6.2 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.1%