obiba / mica2

Mica is a web portal for epidemiological study consortia.
http://www.obiba.org/pages/products/mica/
GNU General Public License v3.0
10 stars 15 forks source link

CVE-2012-6708, CVE-2011-4969 #4445

Open mdc-webdb opened 3 months ago

mdc-webdb commented 3 months ago

This issue is unique

Version information

5.4.1

Expected behavior

No security scanner alarm

Actual behavior

The security scanner will report this: CVE-2012-6708 jQuery is prone to a cross-site scripting (XSS) vulnerability. Installed version: 1.6.1 Fixed version: 1.9.0 Installation path / port: /usr/share/mica2-5.4.1/webapp/bower_components/modernizr/test/caniuse_files/jquery.min.js

CVE-2011-496 Installed version: 1.6.1 Fixed version: 1.6.3 Installation path / port: /usr/share/mica2-5.4.1/webapp/bower_components/modernizr/test/caniuse_files/jquery.min.js

Reproduction steps

No response

Operating System (OS)

Linux

Browser

No response

Contact info

No response