StackRadar

CVE-2021-41184

Medium

Advisory

Published 26 Oct 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.408
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
3 of 3
affected packages

XSS in the `of` option of the `.position()` util in jquery-ui

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
jquery-uinpm1.10.4, 1.12.11.13.010
jquery-ui-railsgem6.0.17.0.01
jqueryuideb1.12.1+dfsg-51.12.1+dfsg-5ubuntu0.18.04.1~esm21
OSV records
GHSA-gpqq-952q-5327UBUNTU-CVE-2021-41184
Also known as
BIT-drupal-2021-41184, USN-5181-1, USN-6419-1

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
deconzgeek-cookbookVerified publisher6.5.21 of 1See more

deconz geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.12.066541bbb78952
jquery-ui@1.12.1
1.13.0

Open the chart page →

3,555
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
kobotoolbox/kpi:2.022.24dbcacc01bccd4
jquery-ui@1.12.1
1.13.0

Open the chart page →

18,517
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
supabase/postgres:17.6.1.136f371b5f3f2ac
jquery-ui@1.12.1
1.13.0

Open the chart page →

18,075
trifidappuio2.0.21 of 1See more

trifid appuio 2.0.2

1 of the 1 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
zazuko/trifid:2.3.7054be137de70
jquery-ui@1.12.1
1.13.0

Open the chart page →

2,783
drupalcetic0.1.01 of 1See more

drupal cetic 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
library/drupal:8-apache8a1a3ee83899
jquery-ui@1.12.1
1.13.0

Open the chart page →

2,504
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
jquery-ui@1.12.1
1.13.0

Open the chart page →

29,901
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
jqueryui@1.12.1+dfsg-5
1.12.1+dfsg-5ubuntu0.18.04.1~esm2

Open the chart page →

27,728
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
jquery-ui@1.12.1
1.13.0

Open the chart page →

8,392
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
jquery-ui@1.12.1
1.13.0

Open the chart page →

10,780
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
jquery-ui-rails@6.0.1
7.0.0

Open the chart page →

9,542
pecanncsaVerified publisher0.6.21 of 15See more

pecan ncsa 0.6.2

1 of the 15 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
jquery-ui-rails@6.0.1
7.0.0

Open the chart page →

14,154
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
jquery-ui@1.12.1
1.13.0

Open the chart page →

27,465
accountingcollegestudentsaccounting0.1.01 of 1See more

accountingcollege studentsaccounting 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-41184.

Container imageDigestPackageFixed in
shadow228/accountingcollege:0.0.28fcea5b71906
jquery-ui@1.10.4
1.13.0

Open the chart page →

1,682

Container images carrying it

12 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
pecan/bety:5.4.1f825d480cd62
jquery-ui-rails@6.0.1
7.0.0
2
daskdev/dask-notebook:1.1.0052630f5ca04
jquery-ui@1.12.1
1.13.0
1
deconzcommunity/deconz:2.29.2062de2362641
jquery-ui@1.12.1
1.13.0
1
deconzcommunity/deconz:2.12.066541bbb78952
jquery-ui@1.12.1
1.13.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
jquery-ui@1.12.1
1.13.0
1
library/drupal:8-apache8a1a3ee83899
jquery-ui@1.12.1
1.13.0
1
linuxserver/codimd:latestb801bbcf6386
jquery-ui@1.12.1
1.13.0
1
opendatacube/wms:latest1b90cdf68831
jqueryui@1.12.1+dfsg-5
1.12.1+dfsg-5ubuntu0.18.04.1~esm2
1
openemr/openemr:6.1.089eaa6d9a4e3
jquery-ui@1.12.1
1.13.0
1
shadow228/accountingcollege:0.0.28fcea5b71906
jquery-ui@1.10.4
1.13.0
1
supabase/postgres:17.6.1.136f371b5f3f2ac
jquery-ui@1.12.1
1.13.0
1
zazuko/trifid:2.3.7054be137de70
jquery-ui@1.12.1
1.13.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.