Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security exposure in the packaged jquery library #15035

Closed
scottdickerson opened this issue Aug 12, 2019 · 5 comments
Closed

security exposure in the packaged jquery library #15035

scottdickerson opened this issue Aug 12, 2019 · 5 comments

Comments

@scottdickerson
Copy link

Upgraded to matplotlib version 3.1.1 but there is still a flagged security exposure by our security scan tool

/Users/scottsd/Documents/GitHub/analytics-service-library/env/lib/python3.7/site-packages/matplotlib/backends/web_backend/jquery-ui-1.12.1/external/jquery/jquery.js

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11358

image

Please upgrade the packaged version of jquery to fix the security exposure

@anntzer
Copy link
Contributor

anntzer commented Aug 26, 2019

Our version of jquery is the one that comes with the download of jqueryui at https://jqueryui.com; can you ask them to update their bundled jquery?

@scottdickerson
Copy link
Author

I opened this bug over there:
https://bugs.jqueryui.com/ticket/15353#ticket

@scottdickerson
Copy link
Author

no updates from JQueryUI, any way you could update to a more recent version?

@anntzer
Copy link
Contributor

anntzer commented Dec 19, 2019

Someone would need to write a patch, I don't think(?) any of the active core devs would consider themselves a specialist of that part of the codebase.

@timhoffm
Copy link
Member

Since Matplotlib 3.3.0 we do not depend on jquery any longer. c.f. #17086.

@QuLogic QuLogic added this to the v3.3.0 milestone Jul 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants