DRUPAL-CONTRIB-2022-004
Details
jQuery UI is a third-party library used by Drupal. The jQuery UI Datepicker module provides the jQuery UI Datepicker library, which is not included in Drupal 9 core.
jQuery UI was previously thought to be end-of-life.
Late in 2021, jQuery UI announced that they would be continuing development, and released a [jQuery UI 1.13.0](https://blog.jqueryui.com/2021/10/jquery-ui-1-13-0-released/) version. As part of this 1.13.0 update, they disclosed the following security issues that may affect site using the jQuery UI Datepicker module:
* CVE-2021-41182: [XSS in the altField option of the Datepicker widget](https://github.com/jquery/jquery-ui/security/advisories/GHSA-9gj3-hwp5-pmwc) * CVE-2021-41183: [XSS in \*Text options of the Datepicker widget](https://github.com/jquery/jquery-ui/security/advisories/GHSA-j7qv-pgf6-hvh4)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.2.0Upgrade drupal/jquery_ui_datepicker to 1.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).