Bug 266905 - ports-mgmt/poudriere: consider an upgrade to JQuery
Summary: ports-mgmt/poudriere: consider an upgrade to JQuery
Status: New
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Some People
Assignee: Bryan Drewery
Depends on:
Reported: 2022-10-08 14:42 UTC by Ian Dickens
Modified: 2024-06-18 18:17 UTC (History)
2 users (show)

See Also:
bugzilla: maintainer-feedback? (bdrewery)


Note You need to log in before you can comment on or make changes to this bug.
Description Ian Dickens 2022-10-08 14:42:38 UTC
Is there any way to bump up the jquery version from 1.11.1 to something newer?  Nessus is reporting that that version is vulnerable.  File location is /usr/local/share/poudriere/html/assets/jquery-1.11.1.min.js.  The blurb from the scan is:

JQuery 1.2 < 3.5.0 Multiple XSS
According to the self-reported version in the script, the version of JQuery hosted on the remote web server is greater than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities.

Note, the vulnerabilities referenced in this plugin have no security impact on PAN-OS, and/or the scenarios required for successful exploitation do not exist on devices running a PAN-OS release.
Upgrade to JQuery version 3.5.0 or later.
See Also


Comment 1 Siva Mahadevan 2024-06-18 18:17:34 UTC
This can be closed now, current bundled version is 3.7.1.