Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-71139

Update jQuery to avoid CVE-2020-11022 and CVE-2020-11023

XMLWordPrintable

      Issue Summary

      Currently, Jira runs with jQuery version 2.2.4, which is susceptible to the following vulnerabilities:

      https://nvd.nist.gov/vuln/detail/CVE-2020-11023
      https://nvd.nist.gov/vuln/detail/CVE-2020-11022

      Steps to Reproduce

      -

      Expected Results

      We should update the version of jQuery to at least version 3.5.0, where these vulnerabilities are no longer present.

      Actual Results

      Jira uses jQuery version 2.2.4

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

              mrzymski Maciej Rzymski
              lbugs Lucas Bugs
              Votes:
              0 Vote for this issue
              Watchers:
              16 Start watching this issue

                Created:
                Updated:
                Resolved: