View Issue Details

This bug affects 1 person(s).
 250
IDProjectCategoryView StatusLast Update
19493Bug reportsSecuritypublic2024-03-21 13:57
ReporterLDBV Assigned To 
PrioritynoneSeverityminor 
Status newResolutionopen 
Product Version6.4.x 
Summary19493: underscore.js 1.8.3 has an Arbitrary Code Injection security vulnerability
Description

Greetings,

we had a Pen-Test for our LimeSurvey V6 Server. The testers have found several critical security problems (we open different bug report tickets).

adminsidepanel.js depends on underscore.js (You can find it under the path .../limesurvey/tmp/assets/.../build.min/js).

underscore.js 1.8.3 has an Arbitrary Code Injection security vulnerability (https://security.snyk.io/package/npm/underscore/1.8.3).

The current version is underscore.js 1.13.6 (solving this security vulnerability).

Thanks.

TagsNo tags attached.
Bug heat250
Complete LimeSurvey version number (& build)both 6.4.6+240212 and 6.5.0+240319
I will donate to the project if issue is resolvedNo
BrowserRegardless of the browser
Database type & versionMySQL 8.0.36
Server OS (if known)SLES 15.5
Webserver software & version (if known)Apache 2.4.51
PHP VersionPHP 8.0.30

Users monitoring this issue

There are no users monitoring this issue.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2024-03-21 13:57 LDBV New Issue