Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security report jQuery@1.11.1 #1874

Closed
jurjendevries opened this issue Apr 5, 2021 · 2 comments
Closed

Security report jQuery@1.11.1 #1874

jurjendevries opened this issue Apr 5, 2021 · 2 comments

Comments

@jurjendevries
Copy link

Ossn version: 5.6 paid
PHP version: 7.4
Error message: None
Error Log: n/a
Issue screenshots: n/a
Cache: enabled

jQuery@1.11.1 which is part of OSSN 5.6 is having a Cross-site scripting (XSS) security report https://www.cvedetails.com/cve/CVE-2019-11358/
My suggestion would be to update jQuery to the latest version.

@lianglee
Copy link
Member

lianglee commented Apr 5, 2021

Yesterday I have moved to Jquery 2.2.4 87114ec

However its XSS vulnerability/bug have no effect on OSSN, we don't store same data supplied by any input it is sanitized before going into the system.

@lianglee
Copy link
Member

lianglee commented Apr 5, 2021

Besides that UI is updated to 1.12.1 87114ec

lianglee added a commit that referenced this issue Apr 9, 2021
lianglee added a commit that referenced this issue Apr 9, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants