Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable version of the library 'jquery-ui-dialog' v1.10.0 #12960

Closed
markuman opened this issue Dec 10, 2018 · 3 comments
Closed

Vulnerable version of the library 'jquery-ui-dialog' v1.10.0 #12960

markuman opened this issue Dec 10, 2018 · 3 comments
Labels
0. Needs triage Pending check for reproducibility or if it fits our roadmap bug security

Comments

@markuman
Copy link

Nextcloud 14.0.4 delivers jquery-ui-dialog version v1.10.0

#6340

head -n1 /var/www/nextcloud/core/vendor/jquery-ui/ui/minified/jquery-ui.custom.min.js 
/*! jQuery UI - v1.10.0 - 2013-01-18

The library jquery-ui-dialog version 1.10.0 (The vulnerability is affecting all versions prior 1.12.0) has known security issues.
For more information, visit those websites:

@markuman markuman added 0. Needs triage Pending check for reproducibility or if it fits our roadmap bug labels Dec 10, 2018
@skjnldsv
Copy link
Member

@ChristophWurst our dependency lord and master

@ChristophWurst
Copy link
Member

I gave it a try, but there were too many changes from v1.10 to v1.12 as that could simply update it. See for youself: https://github.com/nextcloud/server/tree/stable14-update-jquery-ui. The sharing autocompletion, for example, has a different styling with the new version.

@skjnldsv
Copy link
Member

Fixed since 17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
0. Needs triage Pending check for reproducibility or if it fits our roadmap bug security
Projects
None yet
Development

No branches or pull requests

4 participants