Current Decipher is using jQuery 1.9, which is highlighted by our IT security team that there are some vulnerabilities that the remote web server is affected by multiple cross site scripting vulnerability. According to the self-reported version in the script, the version of JQuery hosted on the remote web server is greater than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities.
https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/
https://security.paloaltonetworks.com/PAN-SA-2020-0007
Upgrade to JQuery version 3.5.0 or later is required. Please advise on how to do that for all decipher services. I understand we need modify a few index.html files to point to the later version on JQuery.
We need a release timeline to fix the vulnerabilities before the actual implementation of Decipher.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.