MicrosoftDocs / feedback

📢 docs.microsoft.com site feedback
https://learn.microsoft.com
Creative Commons Attribution 4.0 International
239 stars 160 forks source link

Dependence out of date jquery 2.2.4 [CVE-2015-9251] #2370

Open mairaw opened 4 years ago

mairaw commented 4 years ago

From @mozts2005 on Thursday, June 7, 2018 8:00:44 AM

the docs website looks to be using an older version of Jquery 2.2.4 which has known security issues See https://www.cvedetails.com/cve/CVE-2015-9251/

I think an update to a version of 3.0.0 or higher will fix the issue. I would submit a pull request with this issue but I have been unable to find the template.

edit: I now think the template is part of the https://github.com/Microsoft/templates.docs.msft repo which is not public.

Copied from original issue: dotnet/docs#5850

mairaw commented 4 years ago

@adkinn @DuncanmaMSFT this is a very old issue filed in our repo back in 2018 that we failed to triage earlier. Please take a look if this is still the case or not.

Duncanma commented 4 years ago

@mairaw @adkinn It is on our roadmap to remove the jQuery dependency completely, but we'll take this into account. Thanks