Menu

#392 XSS in bundled jquery-ui

Major
closed
nobody
None
1
2018-10-19
2017-10-05
No

mrbs 1.6.1 is bundling jquery-ui 1.11.2 which is known to be vulnerable to an XSS.
http://www.cvedetails.com/cve/CVE-2016-7103/

Discussion

  • Campbell Morrison

    Ok, thanks. I will take a look tomorrow.

     
  • Campbell Morrison

    I have now fixed this in the default branch in f92a4e by upgrading to jQuery UI 1.12.1 and jQuery 3.2.1.

     
  • Xavier Bachelot

    Xavier Bachelot - 2017-10-12

    Thank you.
    Are you planning an mrbs release to fix this ?

     
  • Campbell Morrison

    Yes, we'll be making a 1.6.2 release in the next couple of months.

     
  • Campbell Morrison

    The 1.6.2 release turned out to be the 1.7.0 release.

     
  • Campbell Morrison

    • status: open --> closed