{"id":"GHSA-g8q2-24jh-5hpc","summary":"High severity vulnerability that affects jquery-ui","details":"Withdrawn, accidental duplicate publish.\n\nCross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.","modified":"2024-12-08T05:34:59.232598Z","published":"2018-07-27T14:47:52Z","withdrawn":"2020-06-16T21:36:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:36:34Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-7103"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g8q2-24jh-5hpc"}],"affected":[{"package":{"name":"jquery-ui","ecosystem":"npm","purl":"pkg:npm/jquery-ui"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.12.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-g8q2-24jh-5hpc/GHSA-g8q2-24jh-5hpc.json"}},{"package":{"name":"jQuery.UI.Combined","ecosystem":"NuGet","purl":"pkg:nuget/jQuery.UI.Combined"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.0"}]}],"versions":["1.10.0","1.10.1","1.10.2","1.10.3","1.10.4","1.11.0","1.11.1","1.11.2","1.11.3","1.11.4","1.8.10","1.8.11","1.8.12","1.8.13","1.8.14","1.8.15","1.8.16","1.8.17","1.8.18","1.8.19","1.8.20","1.8.20.1","1.8.21","1.8.22","1.8.23","1.8.24","1.8.9","1.9.0","1.9.0-RC1","1.9.1","1.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-g8q2-24jh-5hpc/GHSA-g8q2-24jh-5hpc.json"}},{"package":{"name":"org.webjars.npm:jquery-ui","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/jquery-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.0"}]}],"versions":["1.10.4","1.10.5","1.12.0-rc.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-g8q2-24jh-5hpc/GHSA-g8q2-24jh-5hpc.json"}},{"package":{"name":"jquery-ui-rails","ecosystem":"RubyGems","purl":"pkg:gem/jquery-ui-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.0"}]}],"versions":["0.0.1","0.0.2","0.1.0","0.2.0","0.2.1","0.2.2","0.3.0","0.4.0","0.4.1","0.5.0","1.0.0","1.1.0","1.1.1","2.0.0","2.0.1","2.0.2","3.0.0","3.0.1","4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.1.0","4.1.1","4.1.2","4.2.0","4.2.1","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-g8q2-24jh-5hpc/GHSA-g8q2-24jh-5hpc.json"}}],"schema_version":"1.9.0"}