Closed
Description
In the latest Doxygen release (1.9.1), the jquery version used is 3.4.1. This version contains two security issue:
- CVE-2020-11022 (https://nvd.nist.gov/vuln/detail/CVE-2020-11022)
- CVE-2020-11023 (https://nvd.nist.gov/vuln/detail/CVE-2020-11023)
jquery have released 3.5.1 to fix it (https://blog.jquery.com/2020/05/04/jquery-3-5-1-released-fixing-a-regression/).
If upgrading to 3.5.x (or 3.6) is too complicated, there is a patch for 3.4.1 that can be applied. See https://github.com/DanielRuf/snyk-js-jquery-565129