Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing security fix for CVE-2019-11358 #38

Closed
jbrarAdobe opened this issue Mar 5, 2020 · 4 comments
Closed

Missing security fix for CVE-2019-11358 #38

jbrarAdobe opened this issue Mar 5, 2020 · 4 comments
Assignees

Comments

@jbrarAdobe
Copy link

Issue in help/release-notes/sp-release-notes.md

Need to add details about the security fix for CVE-2019-11358 which was fixed in SP3 as part of GRANITE-26084
Security - jQuery: Prototype Pollution Vulnerability

@anujkapo
Copy link
Contributor

anujkapo commented Mar 6, 2020

Thanks for reporting the issue. I'll follow-up with the security team. If they have already published this fix in the security bulletin, will include it in the release notes.

@anujkapo anujkapo self-assigned this Mar 6, 2020
@anujkapo
Copy link
Contributor

Hello, I just got a confirmation from the security team that we can include this issue in the Release Notes. I'll add and let you know once the changes are published live. Thanks!

@anujkapo
Copy link
Contributor

Hi Jaideep,

While I was incorporating the updates, I noticed that the key highlights section for 6.5.3.0 already covers jQuery version updates:
https://docs.adobe.com/content/help/en/experience-manager-65/release-notes/service-pack/previous-hotfixes-featurepacks.html
Let me know if we need to capture more details here. Thanks!

@anujkapo
Copy link
Contributor

Hey Jaideep, closing the issue. Let me know in case of any issues. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants