-
Bug
-
Resolution: Done
-
Major
-
None
-
None
-
None
There are some old javascript libraries included in 'externla.min.js' resource which is fetched for 'console/index.html':
Out-of-date Version (Bootstrap)
Identified Version
3.3.7
Latest Version
3.4.1 (in this branch)
Known Vulnerabilities in this Version:
- bootstrap.js CrossSite Scripting (XSS) Vulnerability
External References
CVE201814040 - bootstrap.js CrossSite Scripting (XSS) Vulnerability
External References
CVE201814042 - bootstrap.js CrossSite Scripting (XSS) Vulnerability
External References
CVE201610735
jQuery v3.3.1, contains CVE - https://www.cvedetails.com/cve/CVE-2019-11358/
current version v3.4.1
To be honest, I am not expert in this area, I have not deeply investigate these CVE thus it is possible that our Web Console is not affected by them and as such there is no urgent need to perform bootstrap or jQuery libraries update. Not sure though...
- is incorporated by
-
WFLY-16093 Upgrade HAL to 3.5.11.Final
- Closed
-
WFLY-16094 Upgrade HAL to 3.5.11.Final (WildFly 26.1)
- Closed
- relates to
-
HAL-1542 Replace Grunt with Webpack / Parcel 2.0
- Resolved