An open API service providing security vulnerability metadata for many open source software ecosystems.

MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhwY2YtOHZmOS1xNGdq

Moderate EPSS: 0.01397% (0.79538 Percentile) EPSS:

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Affected Packages Affected Versions Fixed Versions
nuget:jQuery.UI.Combined < 1.12.0 1.12.0
27 Dependent packages
0 Dependent repositories
53,461,818 Downloads total

Affected Version Ranges

All affected versions

1.8.9, 1.8.10, 1.8.11, 1.8.12, 1.8.13, 1.8.14, 1.8.15, 1.8.16, 1.8.17, 1.8.18, 1.8.19, 1.8.20, 1.8.21, 1.8.22, 1.8.23, 1.8.24, 1.9.0, 1.9.1, 1.9.2, 1.10.0, 1.10.1, 1.10.2, 1.10.3, 1.10.4, 1.11.0, 1.11.1, 1.11.2, 1.11.3, 1.11.4

All unaffected versions

1.12.0, 1.12.1, 1.13.0, 1.13.1, 1.13.2, 1.13.3, 1.14.1

maven:org.webjars.npm:jquery-ui < 1.12.0 1.12.0
20 Dependent packages
1 Dependent repositories

Affected Version Ranges

All affected versions

1.10.4, 1.10.5

All unaffected versions

1.12.0, 1.12.1, 1.13.0, 1.13.1, 1.13.2, 1.13.3, 1.14.0, 1.14.1

rubygems:jquery-ui-rails < 6.0.0 6.0.0
311 Dependent packages
43,038 Dependent repositories
81,369,380 Downloads total

Affected Version Ranges

All affected versions

0.0.1, 0.0.2, 0.1.0, 0.2.0, 0.2.1, 0.2.2, 0.3.0, 0.4.0, 0.4.1, 0.5.0, 1.0.0, 1.1.0, 1.1.1, 2.0.0, 2.0.1, 2.0.2, 3.0.0, 3.0.1, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.1.0, 4.1.1, 4.1.2, 4.2.0, 4.2.1, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5

All unaffected versions

6.0.0, 6.0.1, 7.0.0, 8.0.0

npm:jquery-ui < 1.12.0 1.12.0
788 Dependent packages
21,377 Dependent repositories
2,301,363 Downloads last month

Affected Version Ranges

All affected versions

1.10.4, 1.10.5

All unaffected versions

1.12.0, 1.12.1, 1.13.0, 1.13.1, 1.13.2, 1.13.3, 1.14.0, 1.14.1

Affected versions of jquery-ui are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the closeText parameter in the dialog function.

jQuery-UI is a library for manipulating UI elements via jQuery.

Version 1.11.4 has a cross site scripting (XSS) vulnerability in the closeText parameter of the dialog function. If your application passes user input to this parameter, it may be vulnerable to XSS via this attack vector.

Recommendation

Upgrade to jQuery-UI 1.12.0 or later.

References: