-
-
Notifications
You must be signed in to change notification settings - Fork 103
Open
Labels
Description
A customer has brought to our attention a Security Report informing that there are some known vulnerabilities with Javascript libraries, in particular with jQuery 1.11.3 and Bootstrap 3.3.6, which are being used in Mockup.
Information about them can be seen at:
- https://bugs.jquery.com/ticket/11974
- XSS in data-target attribute twbs/bootstrap#20184
- Inadequate/dangerous jQuery behavior for 3rd party text/javascript responses jquery/jquery#2432
My first question would be, are Plone sites vulnerable to attacks using this? I am inclined to answering no, being that there is XSS protection at the server level, but I don't know for sure.
If this affects Plone, should we consider updating jQuery/Bootstrap to patched versions? I mean, we will be updating to newer versions I guess at some point, but if this is affecting security, we might need to do it ASAP.
Thoughts? /cc @thet @petschki @datakurre @sunew @plone/security-team