Object Prototype Pollution Vulnerability (CVE-2019-11358) in jQuery versions prior to 3.4 have been flagged out.
Currently we are using Confluence version 5.10.4 and are looking at ways to upgrade the inbuilt jquery version from 1.7.2 to 3.4. Any suggestions on doing this are welcome.
References:
[1] https://www.zdnet.com/article/popular-jquery-javascript-library-impacted-by-prototype-pollution-flaw/[2] https://snyk.io/blog/after-three-years-of-silence-a-new-jquery-prototype-pollution-vulnerability-emerges-once-again/
Hi!
better way is updagrade to latest Confluence version,
Because a lot of things was changes between 5.10.4
1. https://confluence.atlassian.com/doc/confluence-release-notes-327.html
2. https://community.atlassian.com/t5/Confluence-articles/Confluence-CVEs-and-common-questions/ba-p/1062634
Cheers,
Gonchik Tsymzhitov
It looks like you're new here. Sign in or register to get started.