Tautulli / Tautulli-Issues

Bug reports for Tautulli
18 stars 3 forks source link

Please update Javascript libraries #127

Closed GitGerby closed 3 years ago

GitGerby commented 5 years ago

Version: 2.1.21

Branch: Master

Commit hash: c8575bbc0fb7091e92f316628940acf3790f04da

Operating system:
FreeBSD 11.2-RELEASE-p4 (FreeBSD 11.2-RELEASE-p4 #0: Thu Sep 27 08:16:24 UTC 2018 root@amd64-builder.daemonology.net:/usr/obj/usr/src/sys/GENERIC)

Python version: 2.7.15 (default, May 25 2018, 22:55:00) [GCC 4.2.1 Compatible FreeBSD Clang 4.0.0 (tags/RELEASE_400/final 297347)]

What you did? Lighthouse Audit in Chrome developer tools

What happened? 3 Libraries have known vulnerabilities

What you expected? No vulnerabilities

How can we reproduce your issue?

  1. Using Chrome log in to Tautulli
  2. Open Chrome dev console (keyboard shortcut is ctrl + shift + j)
  3. Select the Audits tab
  4. Select 'Desktop' under Device
  5. Ensure 'Best Practices' is selected under Audits
  6. Click 'Run audits'
  7. Scroll to 'Best Practices' and expand item 4 Includes front-end JavaScript libraries with known security vulnerabilities

What are your (relevant) settings?

Link to logs:

image

JonnyWong16 commented 5 years ago

Acknowledged, but unlikely to be updated anytime soon because there are too many things that would also need to be updated just by upgrading the library versions.

GitGerby commented 5 years ago

Thanks, anything I can do to help let me know.

GitGerby commented 5 years ago

If I have time in the next week I'll look at rolling the libraries forward to their latest patch level if not feature level. Though this is way outside my usual operating scope.

shr00mie commented 5 years ago

not sure if related, but as of the latest docker image, i'm no longer able to load History.

2019-09-11 18:33:19 - ERROR :: CP Server Thread-13 : WebUI :: /history : Uncaught TypeError: Illegal invocation. (jquery-2.1.4.min.js:4)

was working just fine until latest image. tried clearing temp sessions from DB to no avail.

let me know if you need any more info.

samwiseg0 commented 5 years ago

@shr00mie Please do not post unrelated support issues in a bug report. This has been answered in every support channel. Github Issues are not a support channel.

https://github.com/Tautulli/Tautulli-Wiki/wiki/Asking-for-Support

Discord Reddit Plex Forums