• Welcome to the Chevereto user community!

    Here users from all over the world gather around to learn the latest about Chevereto and contribute with ideas to improve the software.

    Please keep in mind:

    • 😌 This community is user driven. Be polite with other users.
    • 👉 Is required to purchase a Chevereto license to participate in this community (doesn't apply to Pre-sales).
    • 💸 Purchase a Pro Subscription to get access to active software support and faster ticket response times.
  • Chevereto Support CLST

    Support response

    Support checklist

JQuery Security vulnerabilities

anyilin

Chevereto Member
Hello developer,
In the latest release (3.13.4), you still use a low-level JQuery (1.x) that has been found to have high-risk security vulnerabilities.
Do you have a plan to upgrade it? (such as upgrading to version 3.4.1)
 

Attachments

  • jq.png
    jq.png
    64.2 KB · Views: 8
It is a real security concern or just these usual harmless stuff that it just get labeled as "critical"? I ask because jquery is used in the user interface, all the real validations are made in the backend.
 
It looks like it is a real security vulnerabilitly

JQuery security vulnerabilities
PCI compliance scan picked up jQuery vulnerabilities:
vulnerable jQuery version: 1.10.2
Details: Two vulnerabilities fixed in jQuery 3.0.0
CVE 2015-9251
CVE 2016-10707

JQuery-ui security vulnerabilitly
jqui.png


And, the content of the first picture of the text is provided by Google Lighthouse.
 
It is a real security concern or just these usual harmless stuff that it just get labeled as "critical"? I ask because jquery is used in the user interface, all the real validations are made in the backend.

Well, do you have a plan to upgrade it?
 
Since it doesn't affect Chevereto it is not something to worry about.

In any case, jquery will get updated in a future revision.
 
Back
Top