View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
16356 | Bug reports | Security | public | 2020-06-02 14:52 | 2020-06-04 12:32 |
Reporter | thermostat | Assigned To | |||
Priority | none | Severity | minor | ||
Status | closed | Resolution | fixed | ||
Product Version | 4.2.5 | ||||
Summary | 16356: Current jquery (3.4.1) has an XSS vulnerability | ||||
Description | The current jquery version has an XSS vulnerability. This has been fixed in 3.5.x. See here for an explanation: https://www.infoq.com/news/2020/04/jquery-35-xss-vulnerability-fix/ It seems it works through the | ||||
Tags | No tags attached. | ||||
Bug heat | 256 | ||||
Complete LimeSurvey version number (& build) | development | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | |||||
Database type & version | Not relevant | ||||
Server OS (if known) | |||||
Webserver software & version (if known) | |||||
PHP Version | Not relevant | ||||
See PR here: https://github.com/LimeSurvey/LimeSurvey/pull/1429 |
|
Yes, but the html injected must have issue :) Still a good idea to update, thanks for the pull request. |
|
Probably true. Most apparent problem here is that company scanners have started to complain, and now Limesurvey is flagged as insecure. So regardless of it being an actual problem, it is a problem in the eyes of the sysadmins :) |
|
Yes :) sure. |
|
Fixed in Release 4.2.7+200604 |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2020-06-02 14:52 | thermostat | New Issue | |
2020-06-02 14:54 | thermostat | Note Added: 58136 | |
2020-06-02 14:55 | DenisChenu | Note Added: 58137 | |
2020-06-02 15:00 | thermostat | Note Added: 58138 | |
2020-06-02 15:19 | DenisChenu | Note Added: 58140 | |
2020-06-04 12:32 | lime_release_bot | Note Added: 58176 | |
2020-06-04 12:32 | lime_release_bot | Status | new => closed |
2020-06-04 12:32 | lime_release_bot | Resolution | open => fixed |