Lucene search

K
nvd[email protected]NVD:CVE-2021-41183
HistoryOct 26, 2021 - 3:15 p.m.

CVE-2021-41183

2021-10-2615:15:10
CWE-79
web.nvd.nist.gov
2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.003 Low

EPSS

Percentile

70.6%

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various *Text options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various *Text options are now always treated as pure text, not HTML. A workaround is to not accept the value of the *Text options from untrusted sources.

Affected configurations

NVD
Node
jqueryuijquery_uiRange<1.13.0jquery
Node
fedoraprojectfedoraMatch33
OR
fedoraprojectfedoraMatch34
OR
fedoraprojectfedoraMatch35
OR
fedoraprojectfedoraMatch36
Node
netapph300s_firmwareMatch-
AND
netapph300sMatch-
Node
netapph500s_firmwareMatch-
AND
netapph500sMatch-
Node
netapph700s_firmwareMatch-
AND
netapph700sMatch-
Node
netapph300e_firmwareMatch-
AND
netapph300eMatch-
Node
netapph500e_firmwareMatch-
AND
netapph500eMatch-
Node
netapph700e_firmwareMatch-
AND
netapph700eMatch-
Node
netapph410s_firmwareMatch-
AND
netapph410sMatch-
Node
netapph410c_firmwareMatch-
AND
netapph410cMatch-
Node
debiandebian_linuxMatch9.0
Node
drupaldrupalRange7.07.86
OR
drupaldrupalRange9.2.09.2.11
OR
drupaldrupalRange9.3.09.3.3
Node
oracleagile_plmMatch9.3.6
OR
oracleapplication_expressRange<22.1.1
OR
oraclebanking_platformMatch2.9.0
OR
oraclebanking_platformMatch2.12.0
OR
oraclebig_data_spatial_and_graphRange<23.1
OR
oraclebig_data_spatial_and_graphMatch23.1
OR
oraclecommunications_interactive_session_recorderMatch6.4
OR
oraclecommunications_operations_monitorMatch4.3
OR
oraclecommunications_operations_monitorMatch4.4
OR
oraclecommunications_operations_monitorMatch5.0
OR
oraclehospitality_inventory_managementMatch9.1.0
OR
oraclehospitality_suite8Range8.11.011.14.0
OR
oraclehospitality_suite8Match8.10.2
OR
oraclejd_edwards_enterpriseone_toolsRange9.2.6.3
OR
oraclemysql_enterprise_monitorRange8.0.29
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.58
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.59
OR
oraclepolicy_automationRange12.2.012.2.5
OR
oracleprimavera_gatewayRange17.717.12
OR
oracleprimavera_gatewayMatch18.8.0
OR
oracleprimavera_gatewayMatch19.12.0
OR
oracleprimavera_gatewayMatch20.12.0
OR
oracleprimavera_gatewayMatch21.12.0
OR
oraclerest_data_servicesRange<22.1.1-
OR
oraclerest_data_servicesMatch22.1.1-
OR
oracleweblogic_serverMatch12.2.1.3.0
OR
oracleweblogic_serverMatch12.2.1.4.0
OR
oracleweblogic_serverMatch14.1.1.0.0
Node
tenabletenable.scRange<5.21.0

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.003 Low

EPSS

Percentile

70.6%