jQuery UI < 1.13.2 Cross-Site Scripting detected on vCenter
search cancel

jQuery UI < 1.13.2 Cross-Site Scripting detected on vCenter

book

Article ID: 442790

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Security scanners detect a Cross-Site Scripting (XSS) vulnerability (CVE-2022-31160) on VMware vCenter Server port 443. The scan reports that the jQuery UI version is earlier than 1.13.2.

  • Security audit reports flag vCenter Server for CVE-2022-31160.

There are 2 services that utilize the jQuery UI, WebSSO and vSphere UI.

Environment

vCenter 8.0

Cause

The vulnerability CVE-2022-31160 specifically affects the checkboxradio widget within the jQuery UI library. While the jQuery UI library is present in the vSphere UI environment, the specific checkboxradio widget is not utilized by the vSphere UI.

Resolution

WebSSO:

This issue is considered non-impacting for VMware vCenter Server. You can safely disregard the security flag for the following reason:

  • No Functional Risk: Engineering has confirmed that the vSphere UI does not use the checkboxradio widget. Because the vulnerable component is not active or utilized, the vulnerability cannot be exploited

If your security policy requires the removal of the detection, please monitor the vCenter Server release notes for future updates containing jQuery UI 1.13.2 or higher.


vSphere-UI:

jQuery UI was updated to 1.13.2 as of vCenter 8.0 U3I Build 24853646