Cross-site scripting in jQuery UI - CVE-2021-41183

 

Cross-site scripting in jQuery UI - CVE-2021-41183

Published: November 20, 2021 / Updated: October 2, 2024


Vulnerability identifier: #VU58270
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2021-41183
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when processing values of various `*Text` options. A remote attacker can pass specially crafted input to the library and execute arbitrary JavaScript code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

jQuery UI
Tenable.sc
Backdrop CMS
Drupal
Moodle
IBM Aspera Faspex for Linux
IBM Aspera Faspex for Windows
IBM Cloud Pak for Watson AIOps
Oracle Business Intelligence Enterprise Edition
IBM Aspera Shares
IBM Engineering Lifecycle Optimization - Publishing
Nessus Network Monitor
Communications Unified Assurance
Fedora
Ubuntu
openEuler
IBM Tivoli Netcool Impact
WebSphere eXtreme Scale
Tenable Nessus
Netcool Operations Insight
IBM Aspera Orchestrator
QRadar User Behavior Analytics
IBM Sterling B2B Integrator
IBM Security Verify Governance
Splunk Enterprise
IBM Security SOAR
SAPUI5
Engineering Lifecycle Management
node-jquery-ui (Ubuntu package)
libjs-jquery-ui (Ubuntu package)
python-XStatic-jquery-ui-help
python3-XStatic-jquery-ui
python-XStatic-jquery-ui
js-jquery-ui
drupal7
IBM API Connect

How to mitigate CVE-2021-41183

Install updates from vendor's website.

jQuery UI - update to 1.13.0
Tenable.sc - update to 5.21.0
Backdrop CMS - update to 1.21.0
Moodle - addressed in versions 3.9.23, 3.11.16
Nessus Network Monitor - update to 6.0.1
Drupal - addressed in versions 7.86, 9.2.11, 9.3.3
IBM Tivoli Netcool Impact - update to 7.1.0.32
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH70967
Tenable Nessus - update to 10.2.0
node-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
libjs-jquery-ui (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.1+dfsg-5ubuntu0.20.04.1
Netcool Operations Insight - update to 1.6.11
IBM Aspera Shares - update to 1.10.0 PL1
python-XStatic-jquery-ui-help - update to 1.12.1.1-2
python3-XStatic-jquery-ui - update to 1.12.1.1-2
python-XStatic-jquery-ui - update to 1.12.1.1-2
js-jquery-ui - addressed in versions 1.13.0-1.el8, 1.13.0-1.fc33, 1.13.0-1.fc34, 1.13.0-1.fc35
IBM Aspera Orchestrator - update to 4.0.1.2b9681
QRadar User Behavior Analytics - update to 4.1.8
IBM Aspera Faspex for Linux - update to 4.4.2
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Sterling B2B Integrator - addressed in versions 6.0.3.8, 6.1.2.2
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
drupal7 - addressed in versions 7.92-1.el7, 7.92-1.fc35, 7.92-1.fc36, 7.92-1.fc37
IBM API Connect - addressed in versions 10.0.1.8, 10.0.5.1
IBM Security Verify Governance - update to 10.0.2.0.1
IBM Security SOAR - update to 44.0

External References

Related Security Bulletins