Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jquery UI security vulnerability #6521

Closed
josvo opened this issue Nov 14, 2018 · 1 comment
Closed

jquery UI security vulnerability #6521

josvo opened this issue Nov 14, 2018 · 1 comment

Comments

@josvo
Copy link

josvo commented Nov 14, 2018

Hello
We are using roundcube old stable 1.2.X. In this version, there is jquery UI in version 1.10.4, which suffers from the following security vulnerability:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7103

Is roundcube therefore also vulnerable?
Thanks
Josef

@alecpl
Copy link
Member

alecpl commented Nov 15, 2018

According to jquery/api.jqueryui.com#281 this is a problem in closeText parameter. Roundcube is not using it.

Anyway, it's unlikely we would update jQuery-ui in Roundcube 1.2.

@alecpl alecpl closed this as completed Nov 15, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants