jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life.
Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issue that may affect Drupal 9 and 7:
CVE-2021-41184: XSS in the `of` option of the `.position()` util
It is possible that this vulnerability is exploitable with some Drupal modules. As a precaution, this Drupal security release applies the fix for the above cross-site description issue, without making any of the other changes to the jQuery version that is included in Drupal.
This advisory is not covered by Drupal Steward.
Install the latest version:
If you are using Drupal 9.3, update to Drupal 9.3.3.
If you are using Drupal 9.2, update to Drupal 9.2.11.
If you are using Drupal 7, update to Drupal 7.86.
All versions of Drupal 8 and 9 prior to 9.2.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.
Chris of the Drupal Security Team
Drew Webber of the Drupal Security Team
Alex Bronstein of the Drupal Security Team
Ben Mullins
xjm of the Drupal Security Team
Théodore Biadala
More Stories
firefox-111.0-1.fc38
FEDORA-2023-ed41d3a922 Packages in this update: firefox-111.0-1.fc38 Update description: Update to latest upstream (111.0) Read More
firefox-111.0-1.fc37
FEDORA-2023-24b2b22eca Packages in this update: firefox-111.0-1.fc37 Update description: Update to latest upstream (111.0) Read More
redis-7.0.10-1.fc37
FEDORA-2023-86068d1187 Packages in this update: redis-7.0.10-1.fc37 Update description: Redis 7.0.10 Released Mon Mar 20 16:00:00 IST 2023 Upgrade urgency: SECURITY,...
redis-7.0.10-1.fc38
FEDORA-2023-e3e1f9dd4d Packages in this update: redis-7.0.10-1.fc38 Update description: Redis 7.0.10 Released Mon Mar 20 16:00:00 IST 2023 Upgrade urgency: SECURITY,...
USN-5965-1: TigerVNC vulnerability
It was discovered that TigerVNC mishandled TLS certificate exceptions. An attacker could use this vulnerability to impersonate any server after...
CVE-2012-10009
A vulnerability was found in 404like Plugin up to 1.0.2. It has been classified as critical. Affected is the function...