Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] Why do we still use a old version of jquery.validation from 2017? #1140

Open
Algorithman opened this issue Jul 12, 2024 · 0 comments

Comments

@Algorithman
Copy link
Contributor

Is there a pressing issue which needs us to use jquery.validation.js v1.17.0 from 2017?
There are a few ReDOS vulnerabilities (which might or might not affect us) which are fixed in the current version (v1.20.1)

CVE-2022-31147
CVE-2021-21252
CVE-2021-43306
and this possible XSS vulnerability: jquery-validation/jquery-validation#2462

I really would like to get rid of specially the XSS vulnerability :)
ReDOS most likely is not applicable for Smartstore.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant