[Bug 1040283] New: CVE-2011-4969: jquery 1.4.4 on software.o.o

http://bugzilla.opensuse.org/show_bug.cgi?id=1040283 Bug ID: 1040283 Summary: CVE-2011-4969: jquery 1.4.4 on software.o.o Classification: openSUSE Product: openSUSE.org Version: unspecified Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Software Portal Assignee: benji@opensuse.org Reporter: astieger@suse.com QA Contact: security-team@suse.de CC: damjanovic.ivo@gmail.com, mrueckert@suse.com Found By: Security Response Team Blocker: --- User reported an issue on static.opensuse.org https://static.opensuse.org/stage/themes/bento/js/jquery.js decleared version is 1.4.4 may be affected by CVE-2011-4969, patched with jquery 1.6.3 I have not found this file in https://github.com/openSUSE/software-o-o Is this a deployment artefact or bundles from somewhere else? Please check -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.opensuse.org/show_bug.cgi?id=1040283 http://bugzilla.opensuse.org/show_bug.cgi?id=1040283#c1 Ivo Damjanovic <contact@damjanovic.rocks> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |contact@damjanovic.rocks --- Comment #1 from Ivo Damjanovic <contact@damjanovic.rocks> --- https://static.opensuse.org/stage/themes/bento/js/jquery.js is loaded on https://de.opensuse.org/Hauptseite another problem is https://de.opensuse.org/load.php?debug=false&lang=de&modules=jquery%2Cmediaw... https://bugs.jquery.com/ticket/11290 jquery 1.8.3 fixed in 1.9.0 I think the bento theme needs an dependencies update. -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.opensuse.org/show_bug.cgi?id=1040283 Ivo Damjanovic <contact@damjanovic.rocks> changed: What |Removed |Added ---------------------------------------------------------------------------- CC|damjanovic.ivo@gmail.com | Component|Software Portal |Wiki -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.opensuse.org/show_bug.cgi?id=1040283 http://bugzilla.opensuse.org/show_bug.cgi?id=1040283#c3 Christian Boltz <suse-beta@cboltz.de> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |suse-beta@cboltz.de Assignee|benji@opensuse.org |tschmidt@suse.com --- Comment #3 from Christian Boltz <suse-beta@cboltz.de> --- AFAIK static.o.o is managed in https://github.com/openSUSE/opensuse-themes (yes, a bit hidden - adjusting the repo description with some search terms would be a good idea) BTW: there's ongoing work for a new wiki theme, see https://en-test.opensuse.org I don't know when it will be ready (as usual, when I test the fix for one bug, I find two new bugs ;-) so I won't promise anything here. Also, the wikis are probably not the only user of static.o.o - but that's something the referrer in the access_log should tell you ;-) Thomas, it seems you did the JS work for static.o.o, therefore I'll reassign this bug to you *eg* -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.opensuse.org/show_bug.cgi?id=1040283 http://bugzilla.opensuse.org/show_bug.cgi?id=1040283#c5 Karl Cheng <qantas94heavy@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED CC| |qantas94heavy@gmail.com Resolution|--- |FIXED --- Comment #5 from Karl Cheng <qantas94heavy@gmail.com> --- software.o.o appears to now use jQuery 1.12.4 instead of 1.4.4. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com