Skip to content

Conversation

@ryw
Copy link
Member

@ryw ryw commented Apr 16, 2020

Resolves XSS CVE present in jquery < 3.5.0
https://app.snyk.io/vuln/SNYK-JS-JQUERY-565129


Make sure to mark the boxes below before creating PR: [x]


In case of fundamental code change, Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in UPDATING.md.
Read the Pull Request Guidelines for more information.

@boring-cyborg boring-cyborg bot added the area:webserver Webserver related Issues label Apr 16, 2020
@codecov-io
Copy link

codecov-io commented Apr 16, 2020

Codecov Report

Merging #8410 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@          Coverage Diff           @@
##           master   #8410   +/-   ##
======================================
  Coverage    6.24%   6.24%           
======================================
  Files         941     941           
  Lines       45606   45606           
======================================
  Hits         2846    2846           
  Misses      42760   42760           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 44ddf54...6849cc5. Read the comment docs.

@ryw ryw changed the title Resolve Cross-site Scripting (XSS) vulnerability SNYK-JS-JQUERY-565129 [WIP] Resolve Cross-site Scripting (XSS) vulnerability SNYK-JS-JQUERY-565129 Apr 19, 2020
@ryw
Copy link
Member Author

ryw commented Apr 19, 2020

This didn't work because we get jQuery from FAB. Opened FAB issue dpgaspar/Flask-AppBuilder#1350

@ryw
Copy link
Member Author

ryw commented Apr 27, 2020

Closing in favor of #8586

@ryw ryw closed this Apr 27, 2020
@ryw ryw deleted the fix-cve-jquery-565129 branch August 26, 2020 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:webserver Webserver related Issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants