Meituan-Dianping / Zebra

美团点评集团统一使用的MySQL数据库访问层的中间件。主要提供对业务开发透明、读写分库、分库分表能力,并提供了端到端SQL监控的集成方案。
Apache License 2.0
2.76k stars 716 forks source link

There is a vulnerability in Bootstrap v3.3.6 ,upgrade recommended #67

Open QiAnXinCodeSafe opened 3 years ago

QiAnXinCodeSafe commented 3 years ago

https://github.com/Meituan-Dianping/Zebra/blob/33d74b831abe7e8e2d29f8c4e145e46ba17432dc/zebra-admin-web/src/main/webapp/app/static/bootstrap/dist/js/bootstrap.min.js#L2

CVE-2019-8331 CVE-2018-14040 CVE-2018-20677 CVE-2018-20676 CVE-2016-10735

Recommended upgrade version:3.4.1