Vulnerability Bulletins

MSA-23-0027: JQuery UI library upgraded to 1.13.2 (upstream)


System information

   
Affected software PHP

Description

by Michael Hawkins. The JQuery UI library included with Moodle has been upgraded to version 1.13.2, which includes fixes for security issues.Severity/Risk:MinorVersions affected:3.11 to 3.11.15, 3.9 to 3.9.22 and earlier unsupported versionsVersions fixed:3.11.16 and 3.9.23Reported by:Wolf VentirCVE identifier:CVE-2022-31160, CVE-2021-41184, CVE-2021-41183 and CVE-2021-41182Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-74544Tracker

More info:

https://moodle.org/mod/forum/discuss.php?d=449648&parent=1807053

Standar resources

Property Value
CVE CVE-2022-31160 ,CVE-2021-41184 ,CVE-2021-41183 and CVE-2021-41182.

Version history

Version Comments Date
1.0 Advisory issued 2023-08-22
Ministerio de Defensa
CNI
CCN
CCN-CERT