DRUPAL-CONTRIB-2022-052
Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2022-052
DRUPAL-CONTRIB-2022-052
Summary:
Details: jQuery UI is a third-party library used by Drupal. The jQuery UI Checkboxradio module provides the jQuery UI Checkboxradio library (which was previously in Drupal 8 core, but has since been removed from core and moved to this module). As part of the jQuery UI 1.13.2 update, the jQuery UI project disclosed following security issue that may affect sites using the jQuery UI Checkboxradio module: * CVE-2022-31160: [XSS when refreshing a checkboxradio with an HTML-like initial text label](https://github.com/jquery/jquery-ui/security/advisories/GHSA-h6gj-6jjq-h8g9)
References: https://www.drupal.org/sa-contrib-2022-052
Affected packages
Package
Name: drupal/jquery_ui_checkboxradio
Purl: pkg:composer/drupal/jquery_ui_checkboxradio?repository_url=https:%2F%2Fpackages.drupal.org%2F8
Affected ranges
Type: ECOSYSTEM
Events:
