rails / jquery-rails

A gem to automate using jQuery with Rails
MIT License
948 stars 406 forks source link

CVE-2019-5428 #270

Closed santosh-1987 closed 4 years ago

santosh-1987 commented 4 years ago

We have a CVE related to jquery 1.2.4- https://www.cvedetails.com/cve/CVE-2019-5428/

Can we install a specific version of jquery-rails (e.g jquery-rails3 / jquery-rails4) in order to get rid of CVE Issues.

kaspth commented 4 years ago

Not sure what you mean. You can install a different gem via your Gemfile and use it's version constraints to help you. Though this is out of scope for the issues tracker, we reserve it for bugs only. Thanks!