Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhwY2YtOHZmOS1xNGdq

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Affected versions of jquery-ui are vulnerable to a cross-site scripting vulnerability when arbitrary user input is supplied as the value of the closeText parameter in the dialog function.

jQuery-UI is a library for manipulating UI elements via jQuery.

Version 1.11.4 has a cross site scripting (XSS) vulnerability in the closeText parameter of the dialog function. If your application passes user input to this parameter, it may be vulnerable to XSS via this attack vector.

Recommendation

Upgrade to jQuery-UI 1.12.0 or later.

Permalink: https://github.com/advisories/GHSA-hpcf-8vf9-q4gj
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhwY2YtOHZmOS1xNGdq
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 6 years ago
Updated: 7 months ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-hpcf-8vf9-q4gj, CVE-2016-7103
References: Repository: https://github.com/jquery/jquery-ui
Blast Radius: 55.7

Affected Packages

nuget:jQuery.UI.Combined
Dependent packages: 0
Dependent repositories: 0
Downloads: 45,318,458 total
Affected Version Ranges: < 1.12.0
Fixed in: 1.12.0
All affected versions: 1.8.9, 1.8.10, 1.8.11, 1.8.12, 1.8.13, 1.8.14, 1.8.15, 1.8.16, 1.8.17, 1.8.18, 1.8.19, 1.8.20, 1.8.21, 1.8.22, 1.8.23, 1.8.24, 1.9.0, 1.9.1, 1.9.2, 1.10.0, 1.10.1, 1.10.2, 1.10.3, 1.10.4, 1.11.0, 1.11.1, 1.11.2, 1.11.3, 1.11.4
All unaffected versions: 1.12.0, 1.12.1, 1.13.0, 1.13.1, 1.13.2
maven:org.webjars.npm:jquery-ui
Dependent packages: 20
Dependent repositories: 1
Downloads:
Affected Version Ranges: < 1.12.0
Fixed in: 1.12.0
All affected versions: 1.10.4, 1.10.5
All unaffected versions: 1.12.0, 1.12.1, 1.13.0, 1.13.1, 1.13.2
rubygems:jquery-ui-rails
Dependent packages: 310
Dependent repositories: 43,038
Downloads: 71,149,005 total
Affected Version Ranges: < 6.0.0
Fixed in: 6.0.0
All affected versions: 0.0.1, 0.0.2, 0.1.0, 0.2.0, 0.2.1, 0.2.2, 0.3.0, 0.4.0, 0.4.1, 0.5.0, 1.0.0, 1.1.0, 1.1.1, 2.0.0, 2.0.1, 2.0.2, 3.0.0, 3.0.1, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.1.0, 4.1.1, 4.1.2, 4.2.0, 4.2.1, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5
All unaffected versions: 6.0.0, 6.0.1, 7.0.0
npm:jquery-ui
Dependent packages: 788
Dependent repositories: 21,377
Downloads: 2,213,093 last month
Affected Version Ranges: < 1.12.0
Fixed in: 1.12.0
All affected versions: 1.10.4, 1.10.5
All unaffected versions: 1.12.0, 1.12.1, 1.13.0, 1.13.1, 1.13.2