jQuery UI is a third-party library used by Drupal. This library was previously thought to be end-of-life.
Late in 2021, jQuery UI announced that they would be continuing development, and released a jQuery UI 1.13.0 version. As part of this 1.13.0 update, they disclosed the following security issue that may affect Drupal 9 and 7:
CVE-2021-41184: XSS in the `of` option of the `.position()` util
It is possible that this vulnerability is exploitable with some Drupal modules. As a precaution, this Drupal security release applies the fix for the above cross-site description issue, without making any of the other changes to the jQuery version that is included in Drupal.
This advisory is not covered by Drupal Steward.
Install the latest version:
If you are using Drupal 9.3, update to Drupal 9.3.3.
If you are using Drupal 9.2, update to Drupal 9.2.11.
If you are using Drupal 7, update to Drupal 7.86.
All versions of Drupal 8 and 9 prior to 9.2.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.
Chris of the Drupal Security Team
Drew Webber of the Drupal Security Team
Alex Bronstein of the Drupal Security Team
Ben Mullins
xjm of the Drupal Security Team
Théodore Biadala
More Stories
firefox-flatpak-120.0-2
FEDORA-FLATPAK-2023-85f15b91dc Packages in this update: firefox-flatpak-120.0-2 Update description: Fixed freezes on Google Maps Update to 120.0 Read More
opendkim-2.11.0-0.36.el9
FEDORA-EPEL-2023-9a05f8b1eb Packages in this update: opendkim-2.11.0-0.36.el9 Update description: Add upstream PR that filters Authentication-Results headers correctly to fix CVE-2022-48521. Read...
firefox-120.0-3.fc37
FEDORA-2023-dce9c4b01f Packages in this update: firefox-120.0-3.fc37 Update description: Fixed freezes on Google Maps Updated to latest upstream (120.0) Read More
SEC Consult SA-20231123 :: Uninstall Key Caching in Fortra Digital Guardian Agent Uninstaller
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Nov 27 SEC Consult Vulnerability Lab Security Advisory < 20231123-0...
SEC Consult SA-20231122 :: Multiple Vulnerabilities in m-privacy TightGate-Pro
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Nov 27 SEC Consult Vulnerability Lab Security Advisory < 20231122-0...
Senec Inverters Home V1, V2, V3 Home & Hybrid Use of Hard-coded Credentials – CVE-2023-39169
Posted by Phos4Me via Fulldisclosure on Nov 27 Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS:...