CWE
79 94
Advisory Published

USN-6419-1: jQuery UI vulnerabilities

First published: Thu Oct 05 2023(Updated: )

Hong Phat Ly discovered that jQuery UI did not properly manage parameters from untrusted sources, which could lead to arbitrary web script or HTML code injection. A remote attacker could possibly use this issue to perform a cross-site scripting (XSS) attack. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103) Esben Sparre Andreasen discovered that jQuery UI did not properly handle values from untrusted sources in the Datepicker widget. A remote attacker could possibly use this issue to perform a cross-site scripting (XSS) attack and execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-41182, CVE-2021-41183) It was discovered that jQuery UI did not properly validate values from untrusted sources. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-41184) It was discovered that the jQuery UI checkboxradio widget did not properly decode certain values from HTML entities. An attacker could possibly use this issue to perform a cross-site scripting (XSS) attack and cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2022-31160)

Affected SoftwareAffected VersionHow to fix
All of
ubuntu/libjs-jquery-ui<1.12.1+dfsg-5ubuntu0.20.04.1
1.12.1+dfsg-5ubuntu0.20.04.1
=20.04
All of
ubuntu/node-jquery-ui<1.12.1+dfsg-5ubuntu0.20.04.1
1.12.1+dfsg-5ubuntu0.20.04.1
=20.04
All of
ubuntu/libjs-jquery-ui<1.12.1+dfsg-5ubuntu0.18.04.1~esm3
1.12.1+dfsg-5ubuntu0.18.04.1~esm3
=18.04
All of
ubuntu/node-jquery-ui<1.12.1+dfsg-5ubuntu0.18.04.1~esm3
1.12.1+dfsg-5ubuntu0.18.04.1~esm3
=18.04
All of
ubuntu/libjs-jquery-ui<1.10.1+dfsg-1ubuntu0.16.04.1~esm1
1.10.1+dfsg-1ubuntu0.16.04.1~esm1
=16.04
All of
ubuntu/libjs-jquery-ui<1.10.1+dfsg-1ubuntu0.14.04.1~esm1
1.10.1+dfsg-1ubuntu0.14.04.1~esm1
=14.04

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Child vulnerabilities

(Contains the following vulnerabilities)

Frequently Asked Questions

  • What is the vulnerability ID for this advisory?

    USN-6419-1

  • What is the title of the vulnerability?

    jQuery UI vulnerabilities

  • Who discovered the vulnerability?

    Hong Phat Ly

  • What is the CVE ID for the cross-site scripting (XSS) attack vulnerability?

    CVE-2021-41183

  • What is the CVE ID for the arbitrary web script or HTML code injection vulnerability?

    CVE-2022-31160

  • What is the severity of the vulnerabilities?

    Based on the CVSS score, the severity of the vulnerabilities is not specified in the advisory.

  • What software versions are affected by the vulnerabilities?

    The vulnerability affects the following versions of jQuery UI: 1.12.1+dfsg-5ubuntu0.20.04.1, 1.12.1+dfsg-5ubuntu0.18.04.1~esm3, 1.10.1+dfsg-1ubuntu0.16.04.1~esm1, and 1.10.1+dfsg-1ubuntu0.14.04.1~esm1.

  • How can the vulnerabilities be exploited?

    The vulnerabilities can be exploited by an attacker to perform cross-site scripting (XSS) attacks or inject arbitrary web script or HTML code.

  • How can I mitigate the vulnerabilities?

    Update the affected software packages to version 1.12.1+dfsg-5ubuntu0.20.04.1, 1.12.1+dfsg-5ubuntu0.18.04.1~esm3, 1.10.1+dfsg-1ubuntu0.16.04.1~esm1, or 1.10.1+dfsg-1ubuntu0.14.04.1~esm1 based on your Ubuntu version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203