openark / orchestrator

MySQL replication topology management and HA
Apache License 2.0
5.61k stars 926 forks source link

JQuery 1.2 Multiple XSS vulnerabilities #1447

Open rlittle316 opened 2 years ago

rlittle316 commented 2 years ago

I see that the packaged version of Jquery is 1.2 in orchestrator. Our security scans found that this is insecure and has multiple cross site scripting vulnerabilities. My request is to upgrade the packaged Jquery to at least 3.5.0 in order to remove these vulnerabilities.

rlittle316 commented 2 years ago

If an upgrade is not possible, is there a way you can package the web ui separately?