-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency jquery to v3 [SECURITY] #15
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-jquery-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
changed the title
Pin dependency jquery to v2.2.4 [SECURITY]
Pin dependency jquery to 2.2.4 [SECURITY]
May 9, 2021
renovate
bot
changed the title
Pin dependency jquery to 2.2.4 [SECURITY]
Pin dependency jquery to v2.2.4 [SECURITY]
May 15, 2021
renovate
bot
changed the title
Pin dependency jquery to v2.2.4 [SECURITY]
Pin dependency jquery to v [SECURITY]
Mar 7, 2022
renovate
bot
changed the title
Pin dependency jquery to v [SECURITY]
Pin dependency jquery to v2.2.4 [SECURITY]
Sep 25, 2022
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
from
November 20, 2022 15:33
b277a39
to
6511288
Compare
renovate
bot
changed the title
Pin dependency jquery to v2.2.4 [SECURITY]
Update dependency jquery to v3 [SECURITY]
Nov 20, 2022
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
from
March 27, 2023 16:53
6511288
to
17a1c8f
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
June 1, 2023 16:09
78f1e66
to
335686f
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
3 times, most recently
from
June 14, 2023 02:27
b4f771c
to
ce7f0bc
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
3 times, most recently
from
June 22, 2023 23:11
e40fafe
to
30de16e
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
July 1, 2023 00:46
b728be0
to
12d36f9
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
4 times, most recently
from
July 11, 2023 05:24
6ee7652
to
7cef7a4
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
4 times, most recently
from
July 21, 2023 05:18
6b70924
to
6ca7689
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
4 times, most recently
from
August 3, 2023 02:33
f73ab92
to
5375429
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
from
August 9, 2023 20:56
5375429
to
83c0bef
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
3 times, most recently
from
May 3, 2024 05:23
0b73017
to
495d9ec
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
May 10, 2024 05:43
3e3db64
to
7331b4a
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
May 23, 2024 11:49
dfcc4fe
to
a04b437
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
June 6, 2024 05:40
4f99988
to
1e6e7f3
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
June 29, 2024 08:41
6812947
to
df11d2b
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
July 15, 2024 05:55
84d8a7d
to
c021bfe
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
4 times, most recently
from
July 29, 2024 05:20
a405863
to
4c99676
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
October 11, 2024 02:35
783c069
to
e970217
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
October 31, 2024 05:42
9f960b9
to
db11099
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
2 times, most recently
from
December 6, 2024 05:29
7067a84
to
1cfac77
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
4 times, most recently
from
December 25, 2024 20:35
545b966
to
04d0088
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
from
January 15, 2025 19:49
04d0088
to
2e515d2
Compare
renovate
bot
force-pushed
the
renovate/npm-jquery-vulnerability
branch
from
January 17, 2025 03:52
2e515d2
to
d8e260d
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.2.1
->^3.5.0
GitHub Vulnerability Alerts
CVE-2020-11023
Impact
Passing HTML containing
<option>
elements from untrusted sources - even after sanitizing them - to one of jQuery's DOM manipulation methods (i.e..html()
,.append()
, and others) may execute untrusted code.Patches
This problem is patched in jQuery 3.5.0.
Workarounds
To workaround this issue without upgrading, use DOMPurify with its
SAFE_FOR_JQUERY
option to sanitize the HTML string before passing it to a jQuery method.References
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
For more information
If you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue.
CVE-2020-11022
Impact
Passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.
.html()
,.append()
, and others) may execute untrusted code.Patches
This problem is patched in jQuery 3.5.0.
Workarounds
To workaround the issue without upgrading, adding the following to your code:
You need to use at least jQuery 1.12/2.2 or newer to be able to apply this workaround.
References
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
https://jquery.com/upgrade-guide/3.5/
For more information
If you have any questions or comments about this advisory, search for a relevant issue in the jQuery repo. If you don't find an answer, open a new issue.
CVE-2015-9251
Affected versions of
jquery
interprettext/javascript
responses from cross-origin ajax requests, and automatically execute the contents injQuery.globalEval
, even when the ajax request doesn't contain thedataType
option.Recommendation
Update to version 3.0.0 or later.
CVE-2019-11358
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles
jQuery.extend(true, {}, ...)
because ofObject.prototype
pollution. If an unsanitized source object contained an enumerable__proto__
property, it could extend the nativeObject.prototype
.Release Notes
jquery/jquery (jquery)
v3.5.0
: jQuery 3.5.0 Released!Compare Source
See the blog post:
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
and the upgrade guide:
https://jquery.com/upgrade-guide/3.5/
NOTE: Despite being a minor release, this update includes a breaking change that we had to make to fix a security issue (
CVE-2020-11022
). Please follow the blog post & the upgrade guide for more details.v3.4.1
Compare Source
v3.4.0
Compare Source
v3.3.1
Compare Source
v3.3.0
Compare Source
v3.2.1
Compare Source
v3.2.0
Compare Source
v3.1.1
Compare Source
v3.1.0
Compare Source
v3.0.0
Compare Source
v2.2.4
Compare Source
v2.2.3
Compare Source
v2.2.2
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.