DependencyTrack / DependencyTrack/dependency-track

Library YUI, version 2.9.0 is vulnerable.

Open
#6,623 0 comments 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

Vulnerable JS Library
**URL**: https:///js/chunk-0eb803bc.fb6b40ab.js
**Evidence**:
```
/yui/license.html
version: 2.9.0
```
**Info**:
The identified library YUI, version 2.9.0 is vulnerable.
- CVE-2012-5882
- CVE-2012-5883

### Steps to Reproduce

**Solution**: Upgrade YUI to [3.18.1](https://security.snyk.io/package/npm/yui/3.18.1)

### Expected Behavior

**Solution**: Upgrade YUI to [3.18.1](https://security.snyk.io/package/npm/yui/3.18.1)

### Dependency-Track Version

5.x

### Browser

Google Chrome

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/main/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Research direction

Start by tracing the reported URL, /js/chunk-0eb803bc.fb6b40ab.js, to the project asset or dependency configuration and confirm where YUI 2.9.0 is included. Check the affected build or dependency path and verify that the generated asset no longer exposes YUI 2.9.0 after upgrading to 3.18.1; done means the reported vulnerable version and CVEs are no longer present.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.