Hi.

The reason for updating jquery is because the jQuery library in versions prior to 3.0.0 is vulnerable to Cross Site Scripting (XSS) attacks when a request is made type Ajax to other domains if the dataType option is not specified.
It is specified in the jQuery Library vulnerable to XSS - CVE-2015-9251.
So a patch should be released to cover this vulnerability for all versions of koha. I am currently using the version 18.11.05 Maintaining updated versions of the components on which koha depends (apache, mysql, jquery, java, perl, php, OS, etc.) allows us to have a secure system. Regards.

El 28/07/2019 a las 07:00 p. m., [email protected] escribió:
Send Koha mailing list submissions to
        [email protected]

To subscribe or unsubscribe via the World Wide Web, visit
        https://lists.katipo.co.nz/mailman/listinfo/koha
or, via email, send a message with subject or body 'help' to
        [email protected]

You can reach the person managing the list at
        [email protected]

When replying, please edit your Subject line so it is more specific
than "Re: Contents of Koha digest..."


Today's Topics:

    1. Re: Update jquery (Owen Leonard)
    2. Re: Update jquery (Paul A)


----------------------------------------------------------------------

Message: 1
Date: Sat, 27 Jul 2019 21:04:06 -0400
From: Owen Leonard <[email protected]>
To: koha <[email protected]>
Subject: Re: [Koha] Update jquery
Message-ID:
        <cao4qe2n374d_0qhcoujpxz5506pek2tjduw1ndrcaxs0-1h...@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"

install jquery v1.7. How can I upgrade to the latest stable version of
jquery?
I would like to hear more details about why you want to upgrade
jQuery. I'm not aware of a reason to do so just for the sake of having
the latest version.

  -- Owen

--

_______________________________________________
Koha mailing list  http://koha-community.org
[email protected]
https://lists.katipo.co.nz/mailman/listinfo/koha

Reply via email to