Skip to content
This repository has been archived by the owner on May 12, 2020. It is now read-only.

Vulnerabilities from jQuery 2.2.4 #21

Open
ghost opened this issue Jun 6, 2018 · 3 comments
Open

Vulnerabilities from jQuery 2.2.4 #21

ghost opened this issue Jun 6, 2018 · 3 comments

Comments

@ghost
Copy link

ghost commented Jun 6, 2018

Including jQuery 2.2.4 inroduces a potential for XSS vulnerabilities, should be upgraded to minimum of 3.0.0.

I'm happy to upgrade and ensure no jQuery related functionality is broken in the process, but wanted to ensure this project was still being maintained / used first.

@hkdobrev
Copy link
Contributor

hkdobrev commented Jun 6, 2018

@jodylecompte Fixing a security issue is always welcome! Could you please send a PR and we could discuss potential BC issues there? Thanks!

@ghost
Copy link
Author

ghost commented Jun 6, 2018

@hkdobrev Certainly, I'll start digging in later this evening. I'm not familiar off the top of the head with what API changes were made in jQuery to warrant the major version upgrade from 2.X to 3.X, but it's possible the upgrade will be entirely painless.

@ghost
Copy link
Author

ghost commented Jun 6, 2018

I meant to include the link to the Snky report in my opening comment, that's what initially tipped me off to the problem.

https://snyk.io/test/npm/jquery/2.2.4

@ghost ghost mentioned this issue Jun 6, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant