spring-projects / spring-projects/spring-data-rest
HAL Browser bundles old jquery version with CVE [DATAREST-1370]
@odrotbohm is already working on this.
Since Dec 31, 2020.
- Dominant language
- Java
- Stars
- 958
- Forks
- 568
- PR merge metrics
- No merged PRs in 30d
Description
honnel opened DATAREST-1370 and commented
The Spring Data Rest HAL Browser uses hal-browser which bundles jquery in very old version with CVE:
hal-browser (javascript) is used by Spring Data Rest HAL Browser as webjar:
The webjar uses following version of hal-browser with jquery in version 1.10.2
The CVE for this jquery version is:
https://nvd.nist.gov/vuln/detail/CVE-2019-11358
Affects: 3.1.6 (Lovelace SR6)
Reference URL: https://github.com/mikekelly/hal-browser/blob/ad9b865f6439652a8a7c683731a45d4fb997477f/vendor/js/jquery-1.10.2.min.js
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.