Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    XSS vulnerability on JQuery < 3.5.0 - ProGet 5.3.4

    Scheduled Pinned Locked Moved Support
    2 Posts 2 Posters 20 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      richard.carpenter_9650
      last edited by

      Hi,

      An internal security scan has flagged the ProGet website as running a vulnerable version of JQuery.
      Do you have plans to upgrade the version of jQuery used in ProGet?
      If so, can you share when this might be released?

      This is the URL that is being reported https://<server>/resources/InedoLib/jquery-1.11.3.min.js?900.0.0.20

      The CVE for this vulnerability is:
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11022

      This page details the issue, the mitigation, and any issues that may be caused.
      https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/

      Thanks,

      1 Reply Last reply Reply Quote 0
      • apxltdA Offline
        apxltd inedo-engineer
        last edited by

        Hello;

        We are aware of the vulnerabilities.

        Our usage of this library is minimal, and we do not use it in a manner that would impact product security (i.e. "passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others). So please consider this a "false positive".

        Upgrading the library to 3.5.0 would add no value to ProGet users, but it would provide significant risk of UI regressions and risk of introducing unknown security vulnerabilities, that haven't yet been reported.

        Founder and CEO, Inedo

        1 Reply Last reply Reply Quote 0

        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

        With your input, this post could be even better 💗

        Register Login
        • 1 / 1
        • First post
          Last post
        Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation