-
Notifications
You must be signed in to change notification settings - Fork 0
Description
CVE-2021-41184 - Medium Severity Vulnerability
Vulnerable Library - jquery-ui-1.8.23.min.js
A curated set of user interface interactions, effects, widgets, and themes built on top of the jQuery JavaScript Library.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.8.23/jquery-ui.min.js
Path to vulnerable library: /vendor/simplesamlphp/simplesamlphp/www/resources/jquery-ui-1.8.js
Dependency Hierarchy:
- ❌ jquery-ui-1.8.23.min.js (Vulnerable Library)
Vulnerability Details
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of option of the .position() util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the of option is now treated as a CSS selector. A workaround is to not accept the value of the of option from untrusted sources.
Publish Date: 2021-10-26
URL: CVE-2021-41184
CVSS 3 Score Details (6.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41184
Release Date: 2021-10-26
Fix Resolution: jquery-ui - 1.13.0
Step up your Open Source Security Game with Mend here