USN-5181-1: jQuery UI vulnerability
9 September 2022
Several security issues were fixed in jQuery UI.
Releases
Packages
- jqueryui - JavaScript UI library for dynamic web applications
Details
It was discovered that jQuery UI did not properly validate the values from
untrusted sources. An attacker could use this vulnerability to cause a crash or
possibly execute arbitrary code. This issue affected only Ubuntu 18.04 ESM and
Ubuntu 20.4 ESM. (CVE-2021-41184)
It was discovered that jQuery UI checkboxradio widget did not properly decode
certain values from HTML entities. An attacker could possibly use this issue to
generate a cross-site scripting(XSS) attack, resulting in a crash or possibly
execute arbitrary code. (CVE-2022-31160)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
-
node-jquery-ui
-
1.13.1+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libjs-jquery-ui
-
1.13.1+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04
-
node-jquery-ui
-
1.12.1+dfsg-5ubuntu0.20.04.1~esm3
Available with Ubuntu Pro
-
libjs-jquery-ui
-
1.12.1+dfsg-5ubuntu0.20.04.1~esm3
Available with Ubuntu Pro
Ubuntu 18.04
-
node-jquery-ui
-
1.12.1+dfsg-5ubuntu0.18.04.1~esm2
Available with Ubuntu Pro
-
libjs-jquery-ui
-
1.12.1+dfsg-5ubuntu0.18.04.1~esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-6419-1: node-jquery-ui, jqueryui, libjs-jquery-ui-docs, libjs-jquery-ui