DependencyTrack / DependencyTrack/dependency-track

Library DOMPurify, version 3.4.9 is vulnerable.

Open Beginner friendly
#6,624 0 comments 0 reactions 0 assignees View on GitHub
defect in triage
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

### Current Behavior

**URL:** https://URL/js/chunk-2d216214.7dc70238.js
**Evidence:**
```
/*! @license DOMPurify 3.4.9
```
**Info**:
- [CWE-471](https://cwe.mitre.org/data/definitions/471.html)
- [CWE-665](https://cwe.mitre.org/data/definitions/665.html)
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882

### Steps to Reproduce

**Solutions:** Upgrade to the latest version of the affected library. [3.4.11](https://security.snyk.io/package/npm/dompurify/3.4.11)

### Expected Behavior

**Solutions:** Upgrade to the latest version of the affected library. [3.4.11](https://security.snyk.io/package/npm/dompurify/3.4.11)

### Dependency-Track Version

5.x

### Browser

Google Chrome

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/main/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported

Contributor guide

Open the contributing guide

Research direction

Start by tracing the bundled URL https://URL/js/chunk-2d216214.7dc70238.js back to the project's JavaScript dependency manifest and build entry point. Check how DOMPurify 3.4.9 is included, update it to 3.4.11, rebuild the bundle, and verify the generated asset no longer contains the vulnerable version.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
64/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.