Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Required
Privileges Required
None
Attack Vector
Network
0

CVE-2021-41184

Disclosure Date: October 26, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of option of the .position() util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the of option is now treated as a CSS selector. A workaround is to not accept the value of the of option from untrusted sources.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.1 Medium
Impact Score:
2.7
Exploitability Score:
2.8
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
Required
Scope (S):
Changed
Confidentiality (C):
Low
Integrity (I):
Low
Availability (A):
None

General Information

Vendors

  • drupal,
  • fedoraproject,
  • jqueryui,
  • netapp,
  • oracle,
  • tenable

Products

  • agile plm 9.3.6,
  • application express,
  • banking platform 2.12.0,
  • banking platform 2.9.0,
  • big data spatial and graph,
  • big data spatial and graph 23.1,
  • communications interactive session recorder 6.4,
  • communications operations monitor 4.3,
  • communications operations monitor 4.4,
  • communications operations monitor 5.0,
  • drupal,
  • fedora 33,
  • fedora 34,
  • fedora 35,
  • fedora 36,
  • h300e firmware -,
  • h300s firmware -,
  • h410c firmware -,
  • h410s firmware -,
  • h500e firmware -,
  • h500s firmware -,
  • h700e firmware -,
  • h700s firmware -,
  • hospitality inventory management 9.1.0,
  • hospitality materials control 18.1,
  • hospitality suite8,
  • hospitality suite8 8.10.2,
  • jd edwards enterpriseone tools,
  • jquery ui,
  • peoplesoft enterprise peopletools 8.58,
  • peoplesoft enterprise peopletools 8.59,
  • policy automation,
  • primavera unifier,
  • primavera unifier 18.8,
  • primavera unifier 19.12,
  • primavera unifier 20.12,
  • primavera unifier 21.12,
  • rest data services,
  • rest data services 22.1.1,
  • tenable.sc,
  • weblogic server 12.2.1.3.0,
  • weblogic server 12.2.1.4.0,
  • weblogic server 14.1.1.0.0

References

Additional Info

Technical Analysis