MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.12k stars 21.19k forks source link

"Acceptable minimum versions" list does not satisfy statement "common JavaScript libraries that do not contain known security flaws" within Microsoft mitigation. #93988

Open solrac149 opened 2 years ago

solrac149 commented 2 years ago

https://github.com/MicrosoftDocs/azure-docs/blob/58f37499b1d9c6143573fc6030ea4c47d8bce578/articles/security/develop/threat-modeling-tool-configuration-management.md?plain=1#L201

"I did a spot check for Jquery 1.7.1 and found the below CVE listing that include vulnerabilities for that version:

https://www.cvedetails.com/vulnerability-list/vendor_id-6538/product_id-11031/year-2020/Jquery-Jquery.html

Should the acceptable minimum version listing be removed, as it is static security guidance that doesn't age well? Instead use wording such as "common JavaScript libraries that do not contain known security flaws, and maintained"


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

JamesTran-MSFT commented 2 years ago

@solrac149 Thanks for your feedback! I've assigned this issue to the author who will investigate and update as appropriate.