jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jqueryui | Dec 9, 2022 | Oct 26, 2021 |
| Drupal | — | Upgrade to drupal version 9.2.1Upgrade to drupal version 9.3.3Upgrade to drupal version 7.86 | Mar 23, 2022 | Oct 26, 2021 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34010914 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 34012040 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 34011596 for version 14.1.1.0.0. | Jul 25, 2022 | Oct 26, 2021 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.0.6Upgrade Splunk Enterprise to version 8.2.12Upgrade Splunk Enterprise to version 9.1.1 | Sep 30, 2025 | Oct 26, 2021 |
| Ubuntu | — | Upgrade node-jquery-uiUpgrade node-jquery-ui (Ubuntu Pro)Upgrade libjs-jquery-ui (Ubuntu Pro)Upgrade libjs-jquery-ui | Mar 22, 2023 | Oct 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub