jQueryUI vulnerability
search cancel

jQueryUI vulnerability

book

Article ID: 431075

calendar_today

Updated On:

Products

VMware Smart Assurance

Issue/Introduction

MnR uses old java files with several CVEs involved found in https://<MnR>:58443/APG/js/apg.frontend.browse.min.js:

  • CVE-2021-41182
  • CVE-2021-41181
  • CVE-2021-41183
  • CVE-2022-31160
  • CVE-2016-7103

Environment

MnR - 7.8

Cause

MnR 7.8 using older jQueryUI version i.e 1.12.1

Resolution

MnR 7.9 version has jQueryUI 1.14.1 where fix for reported vulnerability is available, users are recommended to upgrade MnR to avail the fix.