Details
-
Task
-
Resolution: Duplicate
-
Major
-
None
-
13.10
-
Unknown
-
Description
Update the library to improve security: XWiki 13.10 is using jquery 2.x which isĀ vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed, seeĀ https://nvd.nist.gov/vuln/detail/CVE-2015-9251
Attachments
Issue Links
- duplicates
-
XWIKI-14928 Upgrade to jQuery 3.6.0
-
- Closed
-
- mentioned in
-
Page Loading...