Update jQuery to avoid CVE-2020-11022 and CVE-2020-11023

XMLWordPrintable

    • 7.06
    • 19
    • Severity 3 - Minor
    • 28

      Issue Summary

      Currently, Jira runs with jQuery version 2.2.4, which is susceptible to the following vulnerabilities:

      https://nvd.nist.gov/vuln/detail/CVE-2020-11023
      https://nvd.nist.gov/vuln/detail/CVE-2020-11022

      Steps to Reproduce

      -

      Expected Results

      We should update the version of jQuery to at least version 3.5.0, where these vulnerabilities are no longer present.

      Actual Results

      Jira uses jQuery version 2.2.4

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

            Assignee:
            Maciej Rzymski
            Reporter:
            Lucas Bugs
            Votes:
            0 Vote for this issue
            Watchers:
            16 Start watching this issue

              Created:
              Updated:
              Resolved: