CVE-2022-31160
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
描述
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.
如何修補 CVE-2022-31160
要修補 CVE-2022-31160,請將受影響套件升級到下列已修補版本。
- —升級至 1.12.1+dfsg-8+deb11u2 或更新版本
- —升級至 1.13.2 或更新版本
- —升級至 1.13.2 或更新版本
- —升級至 8.0.0 或更新版本
- —升級至 1.13.2 或更新版本
CVE-2022-31160 正在被利用嗎?
低 — EPSS 為 1.9%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- from 0, < 1.12.1+dfsg-8+deb11u2
- from 0, < 1.13.2
- from 0, < 1.13.2
- from 0, < 8.0.0
- from 0, < 1.13.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |