DependencyTrack / DependencyTrack/dependency-track
Library YUI, version 2.9.0 is vulnerable.
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
Vulnerable JS Library
**URL**: https:///js/chunk-0eb803bc.fb6b40ab.js
**Evidence**:
```
/yui/license.html
version: 2.9.0
```
**Info**:
The identified library YUI, version 2.9.0 is vulnerable.
- CVE-2012-5882
- CVE-2012-5883
### Steps to Reproduce
**Solution**: Upgrade YUI to [3.18.1](https://security.snyk.io/package/npm/yui/3.18.1)
### Expected Behavior
**Solution**: Upgrade YUI to [3.18.1](https://security.snyk.io/package/npm/yui/3.18.1)
### Dependency-Track Version
5.x
### Browser
Google Chrome
### Checklist
- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/main/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
Contributor guide
Research direction
Start by tracing the reported URL, /js/chunk-0eb803bc.fb6b40ab.js, to the project asset or dependency configuration and confirm where YUI 2.9.0 is included. Check the affected build or dependency path and verify that the generated asset no longer exposes YUI 2.9.0 after upgrading to 3.18.1; done means the reported vulnerable version and CVEs are no longer present.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 58/100