{"id":"UBUNTU-CVE-2021-41183","details":"jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.","modified":"2026-03-14T08:55:08.608724Z","published":"2021-10-26T15:15:00Z","related":["USN-6419-1"],"upstream":["CVE-2021-41183"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-41183"},{"type":"REPORT","url":"https://github.com/jquery/jquery-ui/security/advisories/GHSA-j7qv-pgf6-hvh4"},{"type":"REPORT","url":"https://bugs.jqueryui.com/ticket/15284"},{"type":"REPORT","url":"https://github.com/jquery/jquery-ui/pull/1953"},{"type":"REPORT","url":"https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6419-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-41183"}],"affected":[{"package":{"name":"jqueryui","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/jqueryui@1.10.1+dfsg-1ubuntu0.14.04.1~esm1?arch=source&distro=trusty/esm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.1+dfsg-1ubuntu0.14.04.1~esm1"}]}],"versions":["1.10.1+dfsg-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"libjs-jquery-ui","binary_version":"1.10.1+dfsg-1ubuntu0.14.04.1~esm1"},{"binary_name":"libjs-jquery-ui-docs","binary_version":"1.10.1+dfsg-1ubuntu0.14.04.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41183.json"}},{"package":{"name":"jqueryui","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/jqueryui@1.10.1+dfsg-1ubuntu0.16.04.1~esm1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.1+dfsg-1ubuntu0.16.04.1~esm1"}]}],"versions":["1.10.1+dfsg-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"libjs-jquery-ui","binary_version":"1.10.1+dfsg-1ubuntu0.16.04.1~esm1"},{"binary_name":"libjs-jquery-ui-docs","binary_version":"1.10.1+dfsg-1ubuntu0.16.04.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41183.json"}},{"package":{"name":"jqueryui","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/jqueryui@1.12.1+dfsg-5ubuntu0.18.04.1~esm3?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.1+dfsg-5ubuntu0.18.04.1~esm3"}]}],"versions":["1.12.1+dfsg-5","1.12.1+dfsg-5ubuntu0.18.04.1~esm2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"libjs-jquery-ui","binary_version":"1.12.1+dfsg-5ubuntu0.18.04.1~esm3"},{"binary_name":"libjs-jquery-ui-docs","binary_version":"1.12.1+dfsg-5ubuntu0.18.04.1~esm3"},{"binary_name":"node-jquery-ui","binary_version":"1.12.1+dfsg-5ubuntu0.18.04.1~esm3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41183.json"}},{"package":{"name":"jqueryui","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/jqueryui@1.12.1+dfsg-5ubuntu0.20.04.1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.1+dfsg-5ubuntu0.20.04.1"}]}],"versions":["1.12.1+dfsg-5"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libjs-jquery-ui","binary_version":"1.12.1+dfsg-5ubuntu0.20.04.1"},{"binary_name":"libjs-jquery-ui-docs","binary_version":"1.12.1+dfsg-5ubuntu0.20.04.1"},{"binary_name":"node-jquery-ui","binary_version":"1.12.1+dfsg-5ubuntu0.20.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-41183.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}