VDB
Sign up
MEDIUM

GHSA-jrpw-8884-2747

eZ Platform Bundled jQuery affected by CVE-2019-11358

Quick fix

GHSA-jrpw-8884-2747 — ezsystems/ezplatform-admin-ui-assets: upgrade to the fixed version with the command below.

composer require ezsystems/ezplatform-admin-ui-assets:^4.2.0

Details

In eZ Platform 2.x, ezsystems/ezplatform-admin-ui-assets before v4.2.0 includes jQuery version 3.3.1. This version of jQuery is affected by the security vulnerability https://www.cvedetails.com/cve/CVE-2019-11358/ This is fixed in jQuery version 3.4. We recommend that you upgrade your ezsystems/ezplatform-admin-ui-assets to v4.2.0 using Composer. This release includes jQuery 3.4.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ezsystems/ezplatform-admin-ui-assets
Introduced in: 4.0.0Fixed in: 4.2.0
Fixcomposer require ezsystems/ezplatform-admin-ui-assets:^4.2.0

References