-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
tastypie-swagger: jquery-1.8.0.min.js is vulnerable #3436
Comments
Thanks, good to remind us that dependabot doesn't update static dependencies bundled with other dependencies. |
concentricsky/django-tastypie-swagger#140 maybe someone can submit a PR to them :-) At first sight the vulnerabilities don't look to severe, but there might be a lot more not officially known. |
Made few discover,
So maybe I can push a PR on the fork. @valentijnscholten do you know if we have enough tests on th UI to do this kind of upgrade? |
There are no tests covering that, but the only place it is used is on the APIv1 docs: https://defectdojo/api/v1/doc/. |
Version |
removed as part of api v1 removal. |
DefectDojo use django-tastypie-swagger which use JQuery 1.8.0 (vulnerable to multiple security issues).
Finding
File Path: tastypie_swagger\static\tastypie_swagger\js\lib\jquery-1.8.0.min.js
MD5: cd8b0bffc85bb5614385ee4ce3596d07
SHA1: 359c6c1ed98081b9a69eb3513b9deced59c957f9
SHA256:d73e2e1bff9c55b85284ff287cb20dc29ad9165ec09091a0597b61199f330805
References
CVE-2012-6708
CVE-2015-9251
CVE-2019-11358
CVE-2020-11022
CVE-2020-11023
The text was updated successfully, but these errors were encountered: