DependencyTrack / DependencyTrack/dependency-track
Library DOMPurify, version 3.4.9 is vulnerable.
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
### Current Behavior
**URL:** https://URL/js/chunk-2d216214.7dc70238.js
**Evidence:**
```
/*! @license DOMPurify 3.4.9
```
**Info**:
- [CWE-471](https://cwe.mitre.org/data/definitions/471.html)
- [CWE-665](https://cwe.mitre.org/data/definitions/665.html)
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882
### Steps to Reproduce
**Solutions:** Upgrade to the latest version of the affected library. [3.4.11](https://security.snyk.io/package/npm/dompurify/3.4.11)
### Expected Behavior
**Solutions:** Upgrade to the latest version of the affected library. [3.4.11](https://security.snyk.io/package/npm/dompurify/3.4.11)
### Dependency-Track Version
5.x
### Browser
Google Chrome
### Checklist
- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/main/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
Contributor guide
Research direction
Start by tracing the bundled URL https://URL/js/chunk-2d216214.7dc70238.js back to the project's JavaScript dependency manifest and build entry point. Check how DOMPurify 3.4.9 is included, update it to 3.4.11, rebuild the bundle, and verify the generated asset no longer contains the vulnerable version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 64/100