jquery-ui: XSS vulnerability in jQuery.ui.dialog title option
Published Nov 24, 2014
6.1
MEDIUMCVSS 3.1
EPSS 18.35%
Description
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
Affected products
No data.
Configuration 1
- 7.0
Configuration 3
- 35
- 36
Configuration 4
- n/a
Configuration 7
- 9.0
No data.
Red Hat Enterprise Linux 6
ipa-0:3.0.0-47.el6
Fixed · RHSA-2015:1462
Red Hat Enterprise Linux 7
ipa-0:4.1.0-18.el7
Fixed · RHSA-2015:0442
CloudForms Management Engine 5
ruby193-rubygem-jquery-rails
Will not fix
OpenShift Enterprise 1
ruby193-rubygem-jquery-rails
Will not fix
OpenStack Foreman
ruby193-rubygem-jquery-ui-rails
Will not fix
Red Hat Enterprise Linux 6
python-sphinx
Will not fix
Red Hat Enterprise Linux 7
python-sphinx
Will not fix
Red Hat Enterprise Linux 7
yelp-xsl
Will not fix
Red Hat OpenShift Enterprise 2
ruby193-rubygem-jquery-rails
Will not fix
Red Hat OpenStack Platform 4
ruby193-rubygem-jquery-rails
Will not fix
Red Hat Satellite 6
ruby193-rubygem-jquery-ui-rails
Will not fix
Red Hat Software Collections
ror40-rubygem-jquery-rails
Will not fix
Red Hat Software Collections
ruby193-rubygem-jquery-rails
Will not fix
Red Hat Subscription Asset Manager
ruby193-rubygem-jquery-rails
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ipa-0:3.0.0-47.el6 | Fixed | RHSA-2015:1462 |
| Red Hat Enterprise Linux 7 | ipa-0:4.1.0-18.el7 | Fixed | RHSA-2015:0442 |
| CloudForms Management Engine 5 | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| OpenShift Enterprise 1 | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| OpenStack Foreman | ruby193-rubygem-jquery-ui-rails | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | python-sphinx | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | python-sphinx | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | yelp-xsl | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat OpenStack Platform 4 | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat Satellite 6 | ruby193-rubygem-jquery-ui-rails | Will not fix | n/a |
| Red Hat Software Collections | ror40-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat Software Collections | ruby193-rubygem-jquery-rails | Will not fix | n/a |
| Red Hat Subscription Asset Manager | ruby193-rubygem-jquery-rails | Will not fix | n/a |
jquery-ui
npm
Introduced 1.7.0 Fixed 1.10.0org.webjars.npm:jquery-ui
Maven
Introduced 1.7.0 Fixed 1.10.0jQuery.UI.Combined
NuGet
Introduced 1.7.0 Fixed 1.10.0jquery-ui-rails
RubyGems
Introduced 0 Fixed 4.0.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | jquery-ui | 1.7.0 | 1.10.0 |
| Maven | org.webjars.npm:jquery-ui | 1.7.0 | 1.10.0 |
| NuGet | jQuery.UI.Combined | 1.7.0 | 1.10.0 |
| RubyGems | jquery-ui-rails | 0 | 4.0.0 |
Remediation
No remediation recorded yet.
References (32)
- http://bugs.jqueryui.com/ticket/6016 ExploitVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0442.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1462.html vendor-advisoryThird Party Advisory
- http://seclists.org/oss-sec/2014/q4/613 mailing-listMailing ListThird Party Advisory
- http://seclists.org/oss-sec/2014/q4/616 mailing-listMailing ListThird Party Advisory
- http://www.debian.org/security/2015/dsa-3249 vendor-advisoryThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html PatchThird Party Advisory
- http://www.securityfocus.com/bid/71106 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037035 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2010-5312 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1166041 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98696 vdb-entryThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-wcm2-9c89-wmfm Advisory
- https://github.com/jquery/jquery-ui/commit/7e9060c109b928769a664dbcc2c17bd21231b6f3 Vendor Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/jquery-ui-rails/CVE-2010-5312.yml
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E mailing-listMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E mailing-listMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E mailing-listMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2022/01/msg00014.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3 vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4 vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVKIOWSXL2RF2ULNAP7PHESYCFSZIJE3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SGSY236PYSFYIEBRGDERLA7OSY6D7XL4
- https://nvd.nist.gov/vuln/detail/CVE-2010-5312
- https://security.netapp.com/advisory/ntap-20190416-0007 Third Party Advisory
- https://web.archive.org/web/20150316023043/http://www.securityfocus.com/bid/71106
- https://web.archive.org/web/20170316161850/http://www.securitytracker.com/id/1037035
- https://www.cve.org/CVERecord?id=CVE-2010-5312
- https://www.drupal.org/sa-core-2022-002 Third Party Advisory
Change history (0)
No recorded changes yet.