Welcome, Guest ( Customer Panel | Login )




 All Forums
 VPCart Forum
 General help me questions
 jQuery 3.4.1 Vulnerability
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

PaulSpoerry
Starting Member

USA
3 Posts

Posted - May 05 2021 :  10:58:06  Show Profile  Reply with Quote
Google Lighthouse Trust and Safety states two known jQuery 3.4.1 Cross-site Scripting vulnerabilities. Remediation states to upgrade jquery to version 3.5.0 or higher. Has this been looked into / is that a safe update to perform?

"Includes front-end JavaScript libraries with known security vulnerabilities 2 vulnerabilities detected
Some third-party scripts may contain known security vulnerabilities that are easily identified and exploited by attackers."

Library Version: jQuery 3.4.1
Vulnerability Count: 2
Highest Severity: Medium
src: https://snyk.io/vuln/npm:jquery?lh=3.4.1

support
Administrator

4679 Posts

Posted - May 06 2021 :  03:48:43  Show Profile  Visit support's Homepage  Reply with Quote
Hello there,

Thank you for the info.

You can follow our helpnote below to change a config to use latest jquery version:

https://helpnotes.vpcart.com/kb/32-Configuration-Shopa_configasp/1419-Update-Needed-For-The-Config-xLoadJLibJQueryVersion-In-Your-VPCart-9-Site/

Thank you
VPCART ADMIN
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Snitz Forums 2000
0 Item(s)
$0.00