CVE-2021-41182

Aliases:GHSA-9gj3-hwp5-pmwcBIT-drupal-2021-41182
Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 26 Oct 2021, 00:00
Last modified:13 Feb 2025, 16:28

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
22.27% HIGH
22% probability +3.01%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

26 Oct 2021, 00:00
Published
Vulnerability first disclosed
13 Feb 2025, 16:28
Last Modified
Vulnerability information updated

Description

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 22.27% Percentile: 96%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • debiandebian_linux

    9.0

  • drupaldrupal

    ≥ 7.0, < 7.86

  • fedoraprojectfedora

    33 | 34 | 35 | 36

  • RubyGemsjquery-ui-rails

    < 7.0.0

  • jqueryjquery-ui

    < 1.13.0

  • jqueryuijquery_ui

    < 1.13.0

  • org.webjars.npmjquery-ui

    < 1.13.0

  • netapph300e

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e

    na

  • netapph500s_firmware

    na

  • netapph700e

    na

  • netapph700s_firmware

    na

  • Npmjquery-ui

    < 1.13.0

  • NuGetjQuery.UI.Combined

    < 1.13.0

  • oracleagile_plm

    9.3.6

  • oracleapplication_express

    < 22.1.1

  • oraclebanking_platform

    2.9.0 | 2.12.0

  • oraclebig_data_spatial_and_graph

    < 23.1 | 23.1

  • oraclecommunications_interactive_session_recorder

    6.4

  • oraclecommunications_operations_monitor

    4.3 | 4.4 | 5.0

  • oraclehospitality_inventory_management

    9.1.0

  • oraclehospitality_materials_control

    18.1

  • oraclehospitality_suite8

    ≥ 8.11.0, ≤ 8.14.0 | 8.10.2

  • oraclejd_edwards_enterpriseone_tools

    ≤ 9.2.6.3

  • oraclemysql_enterprise_monitor

    ≤ 8.0.29

  • oraclepeoplesoft_enterprise_peopletools

    8.58 | 8.59

  • oraclepolicy_automation

    ≥ 12.2.0, ≤ 12.2.25

  • oracleprimavera_unifier

    17.7 | 17.8 | 17.9 | 17.10 | 17.11 | 17.12 | 18.8 | 19.12 | 20.12 | 21.12 | ≥ 17.7, ≤ 17.12

  • oraclerest_data_services

    < 22.1.1 | 22.1.1

  • UnknownWebLogic Server

    12.2.1.3.0 | 12.2.1.4.0 | 14.1.1.0.0

  • tenabletenable.sc

    < 5.21.0

References (31)