geonetwork / geonetwork/core-geonetwork
jQuery 2.4.2 scan XSS vulnerabilities: Request update jQuery 3.5.0
- Dominant language
- Java
- Stars
- 521
- Forks
- 514
- Avg merge
- 6d 13h
- Merged PRs (30d)
- 19
Description
**Describe the bug**
https://snyk.io/vuln/SNYK-JS-JQUERY-565129 or search for jQuery vulnerability
**To Reproduce**
Accunetix security scan report indicates jQuery 2.4.2 has moderate risk vulnerability
**Expected behavior**
It appears that the new 3.5.0 has fixed a more recent cross site scripting vulnerability, so it appears that we may need to jump all the way to the current version.
**Additional context**
We are also working on resolving this since it is on our critical path. I have posted this issue since it probably exceeds the limits of our understand of the UI code.
https://github.com/geonetwork/core-geonetwork/pull/2520 was the update to jQuery 2.4,2 @PascalLike said :"The upgrade to the latest version 3.3.1 is not safe (and does not work)" Is that a backwards compatibility issue with jQuery 3 in general or specific to 3.3.1?
I will also repeat his request to "let me know is there is any extra precaution to take in these kind of updates."
Contributor guide
Research direction
No file or test is named. Start by reviewing prior PR #2520, the Snyk advisory, and the Accunetix report, then locate the jQuery version and its UI usage. Done means the vulnerable version is updated compatibly and the reported scan no longer flags it.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- jquery
- Domain
- frontend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100