fullstorydev / grpcui

An interactive web UI for gRPC, along the lines of postman
MIT License
5.25k stars 388 forks source link

Update jquery version to > 3.5 due to xss exploit #181

Open lucasmilotichhf opened 2 years ago

lucasmilotichhf commented 2 years ago

Hello,

There is a vulnerability with jquery < 3.5 with remote code execution.

https://nvd.nist.gov/vuln/detail/CVE-2020-11022 https://nvd.nist.gov/vuln/detail/CVE-2020-11023

This pr should fix the issue: https://github.com/fullstorydev/grpcui/pull/180

lucasmilotichhf commented 2 years ago

Sorry to ping you directly @jhump, but maybe this could we dangerous for people who has services public