geonetwork / geonetwork/core-geonetwork

jQuery 2.4.2 scan XSS vulnerabilities: Request update jQuery 3.5.0

Open
#4,772 3 comments 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
521
Forks
514
Avg merge
6d 13h
Merged PRs (30d)
19

Description

**Describe the bug**
https://snyk.io/vuln/SNYK-JS-JQUERY-565129 or search for jQuery vulnerability

**To Reproduce**
Accunetix security scan report indicates jQuery 2.4.2 has moderate risk vulnerability

**Expected behavior**
It appears that the new 3.5.0 has fixed a more recent cross site scripting vulnerability, so it appears that we may need to jump all the way to the current version.

**Additional context**
We are also working on resolving this since it is on our critical path. I have posted this issue since it probably exceeds the limits of our understand of the UI code.

https://github.com/geonetwork/core-geonetwork/pull/2520 was the update to jQuery 2.4,2 @PascalLike said :"The upgrade to the latest version 3.3.1 is not safe (and does not work)" Is that a backwards compatibility issue with jQuery 3 in general or specific to 3.3.1?

I will also repeat his request to "let me know is there is any extra precaution to take in these kind of updates."

Contributor guide

Open the contributing guide

Research direction

No file or test is named. Start by reviewing prior PR #2520, the Snyk advisory, and the Accunetix report, then locate the jQuery version and its UI usage. Done means the vulnerable version is updated compatibly and the reported scan no longer flags it.

Written by the indexing model from the issue text.

Assessment

Tech stack
jquery
Domain
frontend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.