CVE-2021-32850
Summary
| CVE | CVE-2021-32850 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-20 22:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names. This issue is patched in version 2.3.6. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| fix XSS vuln · claviska/jquery-minicolors@ef13482 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 38 Update: sympa-6.2.72-2.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Release 2.3.6 · claviska/jquery-minicolors · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 37 Update: sympa-6.2.72-2.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: sympa-6.2.72-2.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: sympa-6.2.72-2.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| GHSL-2021-1045: Cross-Site Scripting (XSS) in jQuery MiniColors Plugin - CVE-2021-32850 | GitHub Security Lab |
CONFIRM |
securitylab.github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183430 Debian Security Update for jquery-minicolors (CVE-2021-32850)
- 284024 Fedora Security Update for sympa (FEDORA-2023-419ca55dd3)
- 284079 Fedora Security Update for sympa (FEDORA-2023-271b912b2b)