CVE-2021-41184
Published: 26 October 2021
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
Priority
CVSS 3 base score: 6.1
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41184
- https://github.com/jquery/jquery-ui/security/advisories/GHSA-gpqq-952q-5327
- https://github.com/jquery/jquery-ui/commit/effa323f1505f2ce7a324e4f429fa9032c72f280
- https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/
- NVD
- Launchpad
- Debian