Skip to content

JS Libraries with XSS vulnerabilities #865

@frapell

Description

@frapell

A customer has brought to our attention a Security Report informing that there are some known vulnerabilities with Javascript libraries, in particular with jQuery 1.11.3 and Bootstrap 3.3.6, which are being used in Mockup.

Information about them can be seen at:

My first question would be, are Plone sites vulnerable to attacks using this? I am inclined to answering no, being that there is XSS protection at the server level, but I don't know for sure.

If this affects Plone, should we consider updating jQuery/Bootstrap to patched versions? I mean, we will be updating to newer versions I guess at some point, but if this is affecting security, we might need to do it ASAP.

Thoughts? /cc @thet @petschki @datakurre @sunew @plone/security-team

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions