cBioPortal / cbioportal

cBioPortal for Cancer Genomics
https://cbioportal.org
GNU Affero General Public License v3.0
632 stars 480 forks source link

jQuery and Bootstrap security issues, outdated versions #9040

Closed mike-gabriel-fci closed 2 years ago

mike-gabriel-fci commented 2 years ago

Our security scans detected medium vonerabilites for jqery and bootsrap libraries related to outdated versions. I have attached screenshots from the scan for more details. Looks like the issue is related to files below: ../reactapp/prefixed-bootsrap-min.css ../reactapp/common.bundle.js

react_bootstrap react_jquery

alisman commented 2 years ago

Hi Mike,

We will upgrade. Should be in v3.7.15 in a couple weeks. I will let you know.

--Aaron

On Wed, Nov 10, 2021 at 7:05 PM mike-gabriel-fci @.***> wrote:

Our security scans detected medium vonerabilites for jqery and bootsrap libraries related to outdated versions. I have attached screenshots from the scan for more details. Looks like the issue is related to files below: ../reactapp/prefixed-bootsrap-min.css ../reactapp/common.bundle.js

[image: react_bootstrap] https://user-images.githubusercontent.com/44902131/141213006-96cab850-7c2a-4bf0-bf23-832054207027.png [image: react_jquery] https://user-images.githubusercontent.com/44902131/141213009-c43102aa-d17b-45e3-b407-4563b4307c26.png

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/cBioPortal/cbioportal/issues/9040, or unsubscribe https://github.com/notifications/unsubscribe-auth/AABNRGL5WE3IUPOQKVWZZ5LULMCFXANCNFSM5HZGBAOQ . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.