spring-projects / spring-projects/spring-data-rest

HAL Browser bundles old jquery version with CVE [DATAREST-1370]

Open
#1,730 1 comment 0 reactions 1 assignee View on GitHub

@odrotbohm is already working on this.

Since Dec 31, 2020.

in: repository type: bug
Dominant language
Java
Stars
958
Forks
568
PR merge metrics
No merged PRs in 30d

Description

honnel opened DATAREST-1370 and commented

The Spring Data Rest HAL Browser uses hal-browser which bundles jquery in very old version with CVE:

hal-browser (javascript) is used by Spring Data Rest HAL Browser as webjar:

https://github.com/spring-projects/spring-data-rest/blob/master/spring-data-rest-hal-browser/pom.xml#L16

The webjar uses following version of hal-browser with jquery in version 1.10.2

https://github.com/mikekelly/hal-browser/blob/ad9b865f6439652a8a7c683731a45d4fb997477f/vendor/js/jquery-1.10.2.min.js

The CVE for this jquery version is:
https://nvd.nist.gov/vuln/detail/CVE-2019-11358

 


Affects: 3.1.6 (Lovelace SR6)

Reference URL: https://github.com/mikekelly/hal-browser/blob/ad9b865f6439652a8a7c683731a45d4fb997477f/vendor/js/jquery-1.10.2.min.js

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.