Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The identified library DOMPurify, version 2.4.9, is vulnerable. #1143

Closed
2 tasks done
kazenguyen97 opened this issue Jan 20, 2025 · 0 comments
Closed
2 tasks done

The identified library DOMPurify, version 2.4.9, is vulnerable. #1143

kazenguyen97 opened this issue Jan 20, 2025 · 0 comments
Labels
defect Something isn't working
Milestone

Comments

@kazenguyen97
Copy link

Current Behavior

Description: The identified library DOMPurify, version 2.4.9, is vulnerable.

URL: https://{{URL}}/js/chunk-cbf05c10.eba03501.js

Evidence:
/*! @license DOMPurify 2.4.9

Other Info:
CVE-2024-47875, CVE-2024-45801

References:

Proposed Behavior

Update this JS

Checklist

@kazenguyen97 kazenguyen97 added the enhancement New feature or request label Jan 20, 2025
@nscuro nscuro transferred this issue from DependencyTrack/dependency-track Jan 20, 2025
@nscuro nscuro added this to the 4.12.3 milestone Jan 20, 2025
@nscuro nscuro added defect Something isn't working and removed enhancement New feature or request labels Jan 20, 2025
@nscuro nscuro closed this as completed in a75c65b Jan 20, 2025
nscuro added a commit to nscuro/dependency-track-frontend that referenced this issue Jan 20, 2025
Closes DependencyTrack#1143

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: nscuro <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
defect Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants