CVE-2021-41184 (CNNVD-202110-1845)
MEDIUM
中文标题:
Openjs Jquery Ui 跨站脚本漏洞
英文标题:
XSS in the `of` option of the `.position()` util
CVSS分数:
6.5
发布时间:
2021-10-26 00:00:00
漏洞类型:
跨站脚本
状态:
PUBLISHED
数据质量分数:
0.30
数据版本:
v3
漏洞描述
中文描述:
Openjs Jquery Ui是Openjs基金会的一款基于Javascript语言用于创建交互式用户界面的代码库。 Openjs Jquery Ui 1.13.0之前版本存在跨站脚本漏洞,攻击者可以通过.position()选项的值执行任意代码。
英文描述:
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
CWE类型:
CWE-79
标签:
(暂无数据)
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| jquery | jquery-ui | < 1.13.0 | - | - |
cpe:2.3:a:jquery:jquery-ui:<_1.13.0:*:*:*:*:*:*:*
|
| jqueryui | jquery_ui | * | - | - |
cpe:2.3:a:jqueryui:jquery_ui:*:*:*:*:*:jquery:*:*
|
| fedoraproject | fedora | 33 | - | - |
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 34 | - | - |
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 35 | - | - |
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
|
| fedoraproject | fedora | 36 | - | - |
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
|
| netapp | h300s_firmware | - | - | - |
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
|
| netapp | h500s_firmware | - | - | - |
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
|
| netapp | h700s_firmware | - | - | - |
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
|
| netapp | h300e_firmware | - | - | - |
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
|
| netapp | h500e_firmware | - | - | - |
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
|
| netapp | h700e_firmware | - | - | - |
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
|
| netapp | h410s_firmware | - | - | - |
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
|
| netapp | h410c_firmware | - | - | - |
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
|
| drupal | drupal | * | - | - |
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
|
| tenable | tenable.sc | * | - | - |
cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*
|
| oracle | agile_plm | 9.3.6 | - | - |
cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
|
| oracle | application_express | * | - | - |
cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*
|
| oracle | banking_platform | 2.9.0 | - | - |
cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*
|
| oracle | banking_platform | 2.12.0 | - | - |
cpe:2.3:a:oracle:banking_platform:2.12.0:*:*:*:*:*:*:*
|
| oracle | big_data_spatial_and_graph | * | - | - |
cpe:2.3:a:oracle:big_data_spatial_and_graph:*:*:*:*:*:*:*:*
|
| oracle | big_data_spatial_and_graph | 23.1 | - | - |
cpe:2.3:a:oracle:big_data_spatial_and_graph:23.1:*:*:*:*:*:*:*
|
| oracle | communications_interactive_session_recorder | 6.4 | - | - |
cpe:2.3:a:oracle:communications_interactive_session_recorder:6.4:*:*:*:*:*:*:*
|
| oracle | communications_operations_monitor | 4.3 | - | - |
cpe:2.3:a:oracle:communications_operations_monitor:4.3:*:*:*:*:*:*:*
|
| oracle | communications_operations_monitor | 4.4 | - | - |
cpe:2.3:a:oracle:communications_operations_monitor:4.4:*:*:*:*:*:*:*
|
| oracle | communications_operations_monitor | 5.0 | - | - |
cpe:2.3:a:oracle:communications_operations_monitor:5.0:*:*:*:*:*:*:*
|
| oracle | hospitality_inventory_management | 9.1.0 | - | - |
cpe:2.3:a:oracle:hospitality_inventory_management:9.1.0:*:*:*:*:*:*:*
|
| oracle | hospitality_materials_control | 18.1 | - | - |
cpe:2.3:a:oracle:hospitality_materials_control:18.1:*:*:*:*:*:*:*
|
| oracle | hospitality_suite8 | * | - | - |
cpe:2.3:a:oracle:hospitality_suite8:*:*:*:*:*:*:*:*
|
| oracle | hospitality_suite8 | 8.10.2 | - | - |
cpe:2.3:a:oracle:hospitality_suite8:8.10.2:*:*:*:*:*:*:*
|
| oracle | jd_edwards_enterpriseone_tools | * | - | - |
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
|
| oracle | peoplesoft_enterprise_peopletools | 8.58 | - | - |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
|
| oracle | peoplesoft_enterprise_peopletools | 8.59 | - | - |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
|
| oracle | policy_automation | * | - | - |
cpe:2.3:a:oracle:policy_automation:*:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | * | - | - |
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | 18.8 | - | - |
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | 19.12 | - | - |
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | 20.12 | - | - |
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | 21.12 | - | - |
cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
|
| oracle | rest_data_services | * | - | - |
cpe:2.3:a:oracle:rest_data_services:*:*:*:*:-:*:*:*
|
| oracle | rest_data_services | 22.1.1 | - | - |
cpe:2.3:a:oracle:rest_data_services:22.1.1:*:*:*:-:*:*:*
|
| oracle | weblogic_server | 12.2.1.3.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 14.1.1.0.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题
OTHER
cve.org
访问
cve.org
无标题
OTHER
cve.org
访问
cve.org
无标题
OTHER
cve.org
访问
cve.org
FEDORA-2021-51c256bf87
vendor-advisory
cve.org
访问
cve.org
FEDORA-2021-ab38307fc3
vendor-advisory
cve.org
访问
cve.org
FEDORA-2021-013ab302be
vendor-advisory
cve.org
访问
cve.org
无标题
OTHER
cve.org
访问
cve.org
无标题
OTHER
cve.org
访问
cve.org
无标题
OTHER
cve.org
访问
cve.org
无标题
OTHER
cve.org
访问
cve.org
无标题
OTHER
cve.org
访问
cve.org
FEDORA-2022-9d655503ea
vendor-advisory
cve.org
访问
cve.org
FEDORA-2022-bf18450366
vendor-advisory
cve.org
访问
cve.org
无标题
OTHER
cve.org
访问
cve.org
af854a3a-2127-422b-91ae-364da2661108
OTHER
nvd.nist.gov
访问
nvd.nist.gov
CVSS评分详情
3.1 (cna)
MEDIUM
6.5
CVSS向量:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
机密性
NONE
完整性
HIGH
可用性
NONE
时间信息
发布时间:
2021-10-26 00:00:00
修改时间:
2025-11-04 16:09:17
创建时间:
2025-11-11 15:37:02
更新时间:
2025-11-11 15:56:57
利用信息
暂无可利用代码信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-41184 |
2025-11-11 15:21:06 | 2025-11-11 07:37:02 |
| NVD | nvd_CVE-2021-41184 |
2025-11-11 14:57:44 | 2025-11-11 07:45:20 |
| CNNVD | cnnvd_CNNVD-202110-1845 |
2025-11-11 15:12:08 | 2025-11-11 07:56:57 |
版本与语言
当前版本:
v3
主要语言:
EN
支持语言:
EN
ZH
安全公告
暂无安全公告信息
变更历史
v3
CNNVD
2025-11-11 15:56:57
vulnerability_type: 未提取 → 跨站脚本; cnnvd_id: 未提取 → CNNVD-202110-1845; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 跨站脚本
- cnnvd_id: 未提取 -> CNNVD-202110-1845
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2
NVD
2025-11-11 15:45:20
affected_products_count: 1 → 44; references_count: 14 → 15; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 44
- references_count: 14 -> 15
- data_sources: ['cve'] -> ['cve', 'nvd']