Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jquery 3.4.1 has known vulnerabilities: severity: medium #2515

Closed
1 of 2 tasks
rajkeshwar opened this issue Apr 14, 2020 · 4 comments
Closed
1 of 2 tasks

jquery 3.4.1 has known vulnerabilities: severity: medium #2515

rajkeshwar opened this issue Apr 14, 2020 · 4 comments

Comments

@rajkeshwar
Copy link
Contributor

rajkeshwar commented Apr 14, 2020

  • Operating System: macOS 10.15.3 (19D76)
  • Node Version: v10.16.0
  • NPM Version: 6.9.0
  • webpack Version: 4.41.6
  • webpack-dev-server Version: 3.10.3
  • Browser: Google Chrome 80.0.3987.163
  • This is a bug
  • This is a modification request

Code

Expected Behavior

Should not have any vulnerabilities issue.

Actual Behavior

jquery 3.4.1 has known vulnerabilities: severity: medium; summary: Regex in its jQuery.htmlPrefilter sometimes may introduce XSS; https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/

For Bugs; How can we reproduce the behavior?

retire --jspath node_modules/

For Features; What is the motivation and/or use-case for the feature?

@alexander-akait
Copy link
Member

/cc @hiroppy let's update jquery and do release

rajkeshwar added a commit to rajkeshwar/webpack-dev-server that referenced this issue Apr 14, 2020
@alexander-akait
Copy link
Member

Fixed, release will be soon (today)

@JulianMeinhardt
Copy link

Is there any info when this fix will be released?

@alexander-akait
Copy link
Member

In near future

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants