jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jqueryui | Dec 9, 2022 | Oct 26, 2021 |
| Drupal | — | Upgrade to drupal version 7.86Upgrade to drupal version 9.2.1Upgrade to drupal version 9.3.3 | Mar 23, 2022 | Oct 26, 2021 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34011596 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 34012040 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 34010914 for version 12.2.1.3.0. | Jul 25, 2022 | Oct 26, 2021 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.0.6Upgrade Splunk Enterprise to version 9.1.1Upgrade Splunk Enterprise to version 8.2.12 | Sep 30, 2025 | Oct 26, 2021 |
| Ubuntu | — | Upgrade libjs-jquery-ui (Ubuntu Pro)Upgrade libjs-jquery-uiUpgrade node-jquery-ui (Ubuntu Pro)Upgrade node-jquery-ui | Mar 22, 2023 | Oct 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub