Object Prototype Pollution Vulnerability (CVE-2019-11358) in jQuery versions prior to 3.4 have been flagged out.
Currently we are using Confluence version 5.10.4 and are looking at ways to upgrade the inbuilt jquery version from 1.7.2 to 3.4. Any suggestions on doing this are welcome.
References:
[1] https://www.zdnet.com/article/popular-jquery-javascript-library-impacted-by-prototype-pollution-flaw/
[2] https://snyk.io/blog/after-three-years-of-silence-a-new-jquery-prototype-pollution-vulnerability-emerges-once-again/
Hi!
better way is updagrade to latest Confluence version,
Because a lot of things was changes between 5.10.4
1. https://confluence.atlassian.com/doc/confluence-release-notes-327.html
Cheers,
Gonchik Tsymzhitov
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.